Skip to content

Remove dead code from C++ webcore headers, src/js, and pretty_format - #35775

Open
robobun wants to merge 5 commits into
mainfrom
claude/farm/cf1ec6e4/dead-code-cpp-webcore-js-rust
Open

Remove dead code from C++ webcore headers, src/js, and pretty_format#35775
robobun wants to merge 5 commits into
mainfrom
claude/farm/cf1ec6e4/dead-code-cpp-webcore-js-rust

Conversation

@robobun

@robobun robobun commented Jul 25, 2026

Copy link
Copy Markdown
Collaborator

Net -1063 lines (+107 -1170) across 26 files. Each symbol was verified to have zero callers across src/, build/debug/codegen/, and src/codegen/ before deletion; a full debug build plus smoke tests (http2, url, mime, expect, Bun.plugin) pass without them.

No overlap with open dead-code PRs #34965, #34759, #35559, #35437.

C++ webcore headers (never #include'd anywhere, 725 lines)

Leftover from the initial WebKit webcore copy; none are referenced by any #include, cmake glob, or codegen script.

  • EventSender.h (116)
  • JSDOMConstructorNotCallable.h (85)
  • JSDOMConvertVariadic.h (74)
  • JSDOMConvertXPathNSResolver.h (55)
  • JSDOMConvertScheduledAction.h (53)
  • BroadcastChannelIdentifier.h, PortIdentifier.h, WebSocketIdentifier.h (35 each)
  • JSDOMBindingInternalsBuiltins.{h,cpp} (237; every line already commented out)

C++ static helpers and extern "C" functions with zero callers (~195 lines)

  • JSMIMEType.cpp: isHTTPQuotedStringChar, isNotHTTPQuotedStringChar, findFirstInvalidHTTPQuotedStringChar, removeBackslashes, escapeQuoteOrBackslash, encodeParamValue. JSMIMEParams.cpp has its own copies of all of these which are used; the JSMIMEType.cpp copies were never called.
  • BunPlugin.cpp: jsFunctionAppendOn{Load,Resolve}Plugin{Node,Browser}. setupBunPlugin only ever wires the *Bun variants via putDirectNativeFunction.
  • FormatStackTraceForJS.cpp: formatStackTraceToJSValueWithoutPrepareStackTrace (static, never called).
  • BunProcess.cpp: Process_defaultSetter (not in BunProcess.lut.h, not referenced by name).
  • windows/rescle-binding.cpp: rescle__setIcon (its Rust caller was removed in Remove ~39k lines of dead Rust across the workspace #35002; rescle__setWindowsMetadata is the unified replacement).
  • napi.cpp: napi_set_ref, napi_internal_get_version (non-standard N-API symbols; not in any vendor/nodejs header, not referenced by any .rs/.cpp/.ts).
  • node/crypto/CryptoUtil.cpp: Bun__NodeCrypto__createCryptoError.
  • ErrorStackTrace.cpp: Bun__errorInstance__finalize (empty body, never called).

src/js built-in modules (~170 lines)

  • node/child_process.ts: ~130 lines of commented-out E()/makeNodeErrorWithCode/getMessage/ERR_INVALID_ARG_TYPE factory. Replaced by $ERR_* intrinsics; this block has been commented out since be108c0 (2022-11-06).
  • node/url.ts: commented-out fileURLToPath(...args) override.
  • node/http2.ts: top-level consts defined and never referenced: bunTLSConnectOptions, RegExpPrototypeExec, DatePrototypeToUTCString, DatePrototypeGetMilliseconds, kSettingNames (the inverse map kSettingIds is what getUnpackedSettings uses), and throwNotImplemented in the internal/shared destructure.
  • internal/shared.ts: kGetNativeReadableProto symbol (never read anywhere in src/js/ or native).

Rust (~80 lines)

  • runtime/test_runner/pretty_format.rs: ZigFormatter struct + new + Display impl. There are two ZigFormatter types in the tree; every call site (mod.rs, host_fn.rs, RequestContext.rs, JSValue.rs, node_cluster_binding.rs) resolves to bun_jsc::console_object::formatter::ZigFormatter (2-arg new). This 3-arg duplicate over pretty_format::Formatter was unreachable.
  • runtime/bake/dev_server/serialized_failure.rs: 17 lines of commented-out Zig writeJsValue with @panic("TODO").
  • runtime/shell/subproc.rs: 11 lines of commented-out Zig Pipe struct definition.

Verification

  • bun bd builds clean
  • bun bd test on http2, url, mime-api, expect, bun-build-api (plugin), child_process pass (child_process has 3 pre-existing failures on main unrelated to this diff)
  • test/internal/source-lints/dead-symbols-cpp-webcore.test.ts guards against reintroduction; fails on main, passes here

Followups (not in this PR, noted for future sweeps)


[review] gate passed · iteration 2 · 26 files touched

fails on main (without fix)
ASAN without fix: 4 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-cpp-webcore.test.ts
bun test v1.4.0 (4a83700b7)

test/internal/source-lints/dead-symbols-cpp-webcore.test.ts:
27 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static String removeBackslashes/],
28 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static String escapeQuoteOrBackslash/],
29 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static String encodeParamValue/],
30 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static inline bool isHTTPQuotedStringChar/],
31 |   ];
32 |   expect(resurrected(checks)).toEqual([]);
                                   ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static int findFirstInvalidHTTPQuotedStringChar",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static String removeBackslashes",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static String escapeQuoteOrBackslash",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static String encodeParamValue",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp
... (truncated)

release without fix: 4 FAILED
bun test v1.4.0-canary.1 (1498d7b77)

test/internal/source-lints/dead-symbols-cpp-webcore.test.ts:
27 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static String removeBackslashes/],
28 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static String escapeQuoteOrBackslash/],
29 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static String encodeParamValue/],
30 |     ["src/jsc/bindings/webcore/JSMIMEType.cpp", /static inline bool isHTTPQuotedStringChar/],
31 |   ];
32 |   expect(resurrected(checks)).toEqual([]);
                                   ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static int findFirstInvalidHTTPQuotedStringChar",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static String removeBackslashes",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static String escapeQuoteOrBackslash",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static String encodeParamValue",
+   "src/jsc/bindings/webcore/JSMIMEType.cpp: static inline bool isHTTPQuotedStringChar",
+ ]

- Expected  - 1
+ Received  + 7

      at <anonymous> (/workspace/bun/test/internal/source-lints/dead-symbols-cpp-webcore.test.ts:32:
... (truncated)
passes on PR (with fix)
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-cpp-webcore.test.ts
bun test v1.4.0 (4a83700b7)

test/internal/source-lints/dead-symbols-cpp-webcore.test.ts:
(pass) dead C++ static helpers in JSMIMEType.cpp do not reappear [24.82ms]
(pass) dead extern C functions do not reappear [38.53ms]
(pass) dead src/js items do not reappear [29.06ms]
(pass) dead Rust items do not reappear [14.05ms]

 4 pass
 0 fail
 4 expect() calls
Ran 4 tests across 1 file. [7.26s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped)
  target       linux-x64-gnu
  build type   Release
  build dir    ./build/release
  revision     4a83700b7a
  features     baseline

22 deps, 108 codegen, 1171 objects in 5560ms

ninja: Entering directory `/workspace/bun/build/release'
[1/1234] gen bindgenv2
[2/1234] gen .bind.ts → GeneratedBindings.cpp
[3/1234] gen JSBuffer.lut.h
Generating /workspace/bun/build/release/codegen/JSBuffer.lut.h from /workspace/bun/src/jsc/bindings/JSBuffer.cpp
[4/1234] gen ProcessBindingBuffer.lut.h
Generating /workspace/bun/build/release/codegen/ProcessBindingBuffer.lut.h from /workspace/bun/src/jsc/bindings/ProcessBindingBuffer.cpp
[5/1234] gen ProcessBindingConstants.lut.h
Generating /workspace/bun/build/release/codegen/ProcessBindingConstants.lut.h from /workspace/bun/src/jsc/bindings/ProcessBindingConstants.cpp
[6/1234] gen ProcessBindingFs.lut.h
Generating /workspace/bun/build/release/codegen/ProcessBindingFs.lut.h from /workspace/bun/src/jsc/bindings/ProcessBindingFs.cpp
[7/1234] fetch zlib
[zlib] up to date
[8/1234] fetch libjpeg-turbo
[libjpeg-turbo] up to date
[9/1234] fetch tinycc
[tinyc
... (truncated)
diff hotspot
src/js/internal/shared.ts                          |   1 -
 src/js/node/child_process.ts                       | 131 -----------------
 src/js/node/http2.ts                               |  16 +--
 src/js/node/url.ts                                 |  24 ----
 src/jsc/bindings/BunPlugin.cpp                     |  20 ---
 src/jsc/bindings/BunProcess.cpp                    |  11 --
 src/jsc/bindings/ErrorStackTrace.cpp               |   5 -
 src/jsc/bindings/FormatStackTraceForJS.cpp         |  18 ---
 src/jsc/bindings/napi.cpp                          |  16 ---
 src/jsc/bindings/node/crypto/CryptoUtil.cpp        |   6 -
 .../bindings/webcore/BroadcastChannelIdentifier.h  |  35 -----
 src/jsc/bindings/webcore/EventSender.h             | 116 ---------------
 .../webcore/JSDOMBindingInternalsBuiltins.cpp      |  78 ----------
 .../webcore/JSDOMBindingInternalsBuiltins.h        | 159 ---------------------
 .../bindings/webcore/JSDOMConstructorNotCallable.h |  85 -----------
 .../bindings/webcore/JSDOMConvertScheduledAction.h |  53 -------
 src/jsc/bindings/webcore/JSDOMConvertVariadic.h    |  74 ----------
 .../bindings/webcore/JSDOMConvertXPathNSResolver.h |  55 -------
 src/jsc/bindings/webcore/JSMIMEType.cpp            | 106 --------------
 src/jsc/bindings/webcore/PortIdentifier.h          |  35 -----
 src/jsc/bindings/webcore/WebSocketIdentifier.h     |  35 -----
 src/jsc/bindings/windows/rescle-binding.cpp        |  12 --
 src/runtime/bake/dev_server/serialized_failure.rs  |  18 ---
 src/runtime/shell/subproc.rs                       |  12 --
 src/runtime/test_runner/pretty_format.rs           |  51 +------
 .../source-lints/dead-symbols-cpp-webcore.test.ts  |  86 +++++++++++
 26 files changed, 88 insertions(+), 1170 deletions(-)

gate history · 2 passed · 1 rejected · iteration 2

evidence per changed file
file                                                      reads  edits  tests
src/js/internal/shared.ts                                     1      1      0
src/js/node/child_process.ts                                  1      1      0
src/js/node/http2.ts                                          2      2      0
src/js/node/url.ts                                            1      1      0
src/jsc/bindings/BunPlugin.cpp                                1      1      0
src/jsc/bindings/BunProcess.cpp                               1      1      0
src/jsc/bindings/ErrorStackTrace.cpp                          1      1      0
src/jsc/bindings/FormatStackTraceForJS.cpp                    1      1      0
src/jsc/bindings/napi.cpp                                     2      1      0
src/jsc/bindings/node/crypto/CryptoUtil.cpp                   1      1      0
src/jsc/bindings/webcore/BroadcastChannelIdentifier.h         0      0      0
src/jsc/bindings/webcore/EventSender.h                        0      0      0
…/jsc/bindings/webcore/JSDOMBindingInternalsBuiltins.cpp      0      0      0
src/jsc/bindings/webcore/JSDOMBindingInternalsBuiltins.h      0      0      0
src/jsc/bindings/webcore/JSDOMConstructorNotCallable.h        0      0      0
src/jsc/bindings/webcore/JSDOMConvertScheduledAction.h        0      0      0
(+ 10 more files)

Deletes ~1170 lines of unreferenced code across C++, built-in JS, and Rust.
Each symbol was verified to have zero callers across src/, build/debug/codegen/,
and src/codegen/ before deletion, and the debug build plus smoke tests (http2,
url, mime, expect, plugin) pass without them.

C++ webcore headers (never #include'd anywhere, leftover from initial WebKit copy):
  EventSender.h, JSDOMConstructorNotCallable.h, JSDOMConvertVariadic.h,
  JSDOMConvertXPathNSResolver.h, JSDOMConvertScheduledAction.h,
  BroadcastChannelIdentifier.h, PortIdentifier.h, WebSocketIdentifier.h,
  JSDOMBindingInternalsBuiltins.{h,cpp} (entirely commented out)

C++ static helpers and extern "C" functions with zero callers:
  JSMIMEType.cpp: isHTTPQuotedStringChar/isNotHTTPQuotedStringChar/
    findFirstInvalidHTTPQuotedStringChar/removeBackslashes/
    escapeQuoteOrBackslash/encodeParamValue (JSMIMEParams.cpp has live copies)
  BunPlugin.cpp: jsFunctionAppendOn{Load,Resolve}Plugin{Node,Browser}
    (setupBunPlugin only wires the Bun variants)
  FormatStackTraceForJS.cpp: formatStackTraceToJSValueWithoutPrepareStackTrace
  BunProcess.cpp: Process_defaultSetter (not in BunProcess.lut.h)
  rescle-binding.cpp: rescle__setIcon (Rust caller removed in #35002)
  napi.cpp: napi_set_ref, napi_internal_get_version (non-standard N-API)
  CryptoUtil.cpp: Bun__NodeCrypto__createCryptoError
  ErrorStackTrace.cpp: Bun__errorInstance__finalize (empty body)

src/js built-in modules:
  child_process.ts: ~130 lines of commented-out E()/makeNodeErrorWithCode/
    getMessage (replaced by $ERR_* intrinsics; stale since 2022)
  url.ts: commented-out fileURLToPath override
  http2.ts: bunTLSConnectOptions, RegExpPrototypeExec, DatePrototypeToUTCString,
    DatePrototypeGetMilliseconds, kSettingNames (defined, never referenced),
    throwNotImplemented (destructured, never called)
  internal/shared.ts: kGetNativeReadableProto symbol

Rust:
  test_runner/pretty_format.rs: ZigFormatter struct + new + Display impl
    (all call sites resolve to console_object::formatter::ZigFormatter)
  bake/dev_server/serialized_failure.rs: commented-out Zig writeJsValue
  shell/subproc.rs: commented-out Zig Pipe struct definition

A source-lint test guards against reintroduction.
@coderabbitai

coderabbitai Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@robobun, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 2 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 902dde3c-0ae1-46c7-ab62-0572832d82ee

📥 Commits

Reviewing files that changed from the base of the PR and between 9c69be7 and 3d5c5f7.

📒 Files selected for processing (24)
  • src/js/internal/shared.ts
  • src/js/node/child_process.ts
  • src/js/node/http2.ts
  • src/js/node/url.ts
  • src/jsc/bindings/BunPlugin.cpp
  • src/jsc/bindings/BunProcess.cpp
  • src/jsc/bindings/ErrorStackTrace.cpp
  • src/jsc/bindings/FormatStackTraceForJS.cpp
  • src/jsc/bindings/napi.cpp
  • src/jsc/bindings/node/crypto/CryptoUtil.cpp
  • src/jsc/bindings/webcore/BroadcastChannelIdentifier.h
  • src/jsc/bindings/webcore/EventSender.h
  • src/jsc/bindings/webcore/JSDOMBindingInternalsBuiltins.cpp
  • src/jsc/bindings/webcore/JSDOMBindingInternalsBuiltins.h
  • src/jsc/bindings/webcore/JSDOMConstructorNotCallable.h
  • src/jsc/bindings/webcore/JSDOMConvertScheduledAction.h
  • src/jsc/bindings/webcore/JSDOMConvertVariadic.h
  • src/jsc/bindings/webcore/JSDOMConvertXPathNSResolver.h
  • src/jsc/bindings/webcore/JSMIMEType.cpp
  • src/jsc/bindings/webcore/PortIdentifier.h
  • src/jsc/bindings/webcore/WebSocketIdentifier.h
  • src/jsc/bindings/windows/rescle-binding.cpp
  • src/runtime/bake/dev_server/serialized_failure.rs
  • src/runtime/shell/subproc.rs

Comment @coderabbitai help to get the list of available commands.

@robobun

robobun commented Jul 25, 2026

Copy link
Copy Markdown
Collaborator Author
Updated 4:20 AM PT - Aug 2nd, 2026

@robobun, your commit 3d5c5f77322ff8b6f238f6a80b65db3ee0cd92a7 passed in Build #87729! 🎉


🧪   To try this PR locally:

bunx bun-pr 35775

That installs a local version of the PR into your bun-35775 executable, so you can run:

bun-35775 --bun

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — mechanical dead-code sweep, each deletion independently verified as unreferenced.

What was reviewed:

  • Grepped the full tree (--no-ignore) for every removed extern "C" symbol (napi_set_ref, napi_internal_get_version, rescle__setIcon, Bun__NodeCrypto__createCryptoError, Bun__errorInstance__finalize, Process_defaultSetter) — only the new guard test references them.
  • Confirmed none of the deleted webcore headers are #include'd anywhere in src/, and the removed http2.ts consts / kGetNativeReadableProto / pretty_format::ZigFormatter have zero remaining references.
  • New guard test follows the established test/internal/source-lints/ pattern alongside dead-code-escapes.test.ts.
Extended reasoning...

Overview

Net -1063 lines across 26 files, entirely deletions of provably-dead code plus one new source-lint guard test. Five categories: (1) never-#include'd webcore headers copied from WebKit, (2) file-local static C++ helpers in JSMIMEType.cpp whose live copies exist in JSMIMEParams.cpp, (3) extern "C" functions whose Rust/FFI callers were previously removed, (4) commented-out code blocks (some dating to 2022), (5) unused top-level consts in built-in JS modules and an unreachable Rust pub struct. No behavior change; nothing added except the guard test.

Security risks

None. Pure deletions with no new logic, no new inputs, no changed control flow. The removed code was already unreachable.

Level of scrutiny

Medium file count but low per-change complexity. The riskiest category is extern "C" symbols, since they escape both linker dead-code elimination and Rust's dead_code lint — a missing FFI caller would only surface as a link error on the specific target that uses it (e.g. rescle__setIcon is Windows-only). I re-grepped the whole tree with --no-ignore for each of these and found zero callers outside the new guard test. The PR description independently states bun bd builds clean, which the linker would reject if any Rust extern block still declared these. The remaining categories (commented-out blocks, un-#include'd headers, unused module-local consts, file-local statics) are trivially safe.

Other factors

The PR description is thorough — it names the commit that orphaned each symbol where relevant, cross-references open dead-code PRs to avoid overlap, and lists exactly which smoke tests were run. The guard test in test/internal/source-lints/ follows existing precedent (dead-code-escapes.test.ts, no-iostream-include.test.ts) and satisfies REVIEW.md's "test fails on main / passes here" requirement. throwNotImplemented remains exported from internal/shared.ts; only the unused destructure in http2.ts was dropped.

The remaining four tests exercise only files that exist on both main and this
branch, so the fail-before / pass-after round-trip works regardless of how the
deleted-file set is staged.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't find any issues. Every removed symbol I spot-checked has zero remaining references, and the deletions are purely subtractive. Deferring to a human because of the breadth — 26 files across C++/Rust/TS including extern "C" FFI symbols in napi.cpp, CryptoUtil.cpp, and rescle-binding.cpp — but I have no specific concerns.

What was reviewed:

  • Grepped src/ and repo root for every removed extern "C" symbol (napi_set_ref, napi_internal_get_version, Bun__errorInstance__finalize, Bun__NodeCrypto__createCryptoError, rescle__setIcon, Process_defaultSetter) — no Rust/C++/TS callers.
  • Checked BunPlugin.h for dangling declarations of the removed Node/Browser plugin variants — none.
  • Verified none of the deleted webcore headers are #include'd anywhere; verified http2.ts consts and kGetNativeReadableProto are unreferenced.
Extended reasoning...

Overview

Net -1063 lines across 26 files, purely subtractive: 9 unincluded webcore headers deleted outright, unused static/extern "C" helpers removed from BunPlugin.cpp, BunProcess.cpp, FormatStackTraceForJS.cpp, JSMIMEType.cpp, napi.cpp, CryptoUtil.cpp, ErrorStackTrace.cpp, rescle-binding.cpp; commented-out blocks removed from child_process.ts, url.ts, serialized_failure.rs, subproc.rs; unused top-level consts removed from http2.ts and shared.ts; a duplicate ZigFormatter removed from pretty_format.rs. A new source-lint test guards against reintroduction.

Security risks

None. No behavior changes — all removed code was either commented out, static-and-uncalled, or extern "C" with no FFI caller. The napi symbols removed (napi_set_ref, napi_internal_get_version) are non-standard and not part of the public N-API surface, so third-party native modules cannot depend on them.

Level of scrutiny

Medium. Each individual deletion is trivially verifiable (grep for callers), and the compiler/linker would catch most mistakes. The risk is in extern "C" symbols where the linker won't complain until runtime — I grepped every one against src/ and the full repo (including vendor/) and found zero callers. The PR description states build/debug/codegen/ was also checked, and bun bd builds clean.

Other factors

I'm deferring rather than approving because of breadth: 26 files across three languages, several of which are load-bearing subsystems (napi, crypto, BunProcess). While I verified the specific claims and the bug-hunting system found nothing, a human should skim the list to confirm none of these were intentionally kept for pending work (e.g., the BunPlugin Node/Browser variants might have been placeholders for future target: 'node' support — though setupBunPlugin accepts and validates 'node'/'browser' targets but never wires them, so removing the dead handlers doesn't change that). CI build #81269 was still in progress at review time.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found, but this is a 26-file, -1170-line dead-code sweep spanning C++/Rust/TS — worth a maintainer skim to confirm none of these were intentionally kept (e.g. the non-standard napi_set_ref/napi_internal_get_version extern "C" symbols) and that the new test/internal/source-lints/ guard is the pattern you want.

What was reviewed

  • Grepped every deleted extern "C" symbol (napi_set_ref, napi_internal_get_version, Bun__NodeCrypto__createCryptoError, Bun__errorInstance__finalize, rescle__setIcon, Process_defaultSetter, the four jsFunctionAppendOn*Plugin{Node,Browser}) across src/ — zero hits.
  • Grepped all nine deleted webcore headers for #include references — none.
  • Confirmed test_runner/mod.rs imports ZigFormatter from bun_jsc::console_object::formatter (2-arg), not the deleted pretty_format 3-arg duplicate.
  • Verified the removed http2.ts consts and throwNotImplemented destructure have no remaining uses in the file.
Extended reasoning...

Overview

Net -1063 lines across 26 files: nine never-#included webcore headers deleted, ~15 static/extern-"C" C++ functions with zero callers removed, ~170 lines of commented-out or unused src/js code, and three Rust items (a duplicate ZigFormatter plus commented-out Zig leftovers). One new source-lint test guards against reintroduction, following the existing test/internal/source-lints/ pattern.

Security risks

None. Pure deletions of unreachable code; no new logic, no input handling changes.

Level of scrutiny

Medium — the diff is mechanical but wide. The correctness proof is that debug+release builds link cleanly (which they do per the evidence block), and I independently grep-verified every extern "C" and header deletion has zero references in src/. The one class of deletion that can't be fully verified by grep is extern "C" N-API symbols that a third-party native addon might dlsymnapi_set_ref and napi_internal_get_version are non-standard and not in vendor/nodejs headers, so this seems safe, but a maintainer should confirm.

Other factors

The PR description is unusually thorough with per-symbol justification and explicit non-overlap checks against four open dead-code PRs. The new lint test follows the established test/internal/source-lints/ convention (dead-code-escapes.test.ts etc. already exist). Given the breadth and the handful of judgment calls (keeping vs. removing the source-lint guard, extern "C" napi symbols), deferring rather than auto-approving.

@robobun

robobun commented Jul 25, 2026

Copy link
Copy Markdown
Collaborator Author

Status (3d5c5f7, net -1113 lines across 24 files):

Build #87729: 194/196 jobs passed (2 darwin-14-aarch64 test lanes still queued). All test failures are marked [flaky] and passed on retry/alone (node-module-module.test.js, 07827.test.ts, request-clone-leak.test.ts, pretty-format-overflow.test.ts, napi.test.ts GC timing); none touch code in this diff. The darwin link now succeeds after restoring Bun__errorInstance__finalize.

The only red check is robobun/evidence ("no regression test in the diff"), which conflicts with the REVIEW.md rule above. Ready for a maintainer to merge.

Jarred-Sumner added a commit that referenced this pull request Jul 31, 2026
#36426)

Net: +140 / -2783 lines across 55 files.

## What changed

### Dead headers removed (5 files)

- `src/jsc/bindings/webcore/ActiveDOMObject.h` (170 lines): every line
was a `//` comment; the 38 `#include "ActiveDOMObject.h"` sites (plus
one in `src/codegen/generate-jssink.ts`) pulled in nothing. All include
lines removed.
- `src/jsc/bindings/webcore/EventDispatcher.h` (41 lines): `rg -wn
EventDispatcher src/ build/debug/codegen/` finds only a code comment in
EventTarget.cpp and an unrelated WebKit `RemoteLayerTreeEventDispatcher`
mention.
-
`src/jsc/bindings/webcore/{EventModifierInit.h,JSEventModifierInit.h,UIEventInit.h}`
(125 lines): a closed dead cluster;
`convertDictionary<EventModifierInit>` is never called and the files
only reference each other.

### Dead .cpp bodies emptied (4 files, ~700 lines removed)

`ActiveDOMObject.cpp`, `EventDispatcher.cpp`, `JSEventModifierInit.cpp`,
`ncrpyto_engine.cpp` reduced to `#include "config.h"` only. Kept as
files so `scripts/build/unified.ts` bundle composition (32 .cpp per TU
in release) stays stable for the other ~300 files in those directories.

### `HTTPParsers.{h,cpp}` (~1012 lines removed)

Bun only calls `isValidHTTPHeaderValue`, `isValidHTTPToken`,
`isHTTPSpace`, and `Bun__writeHTTPDate` from this file (callers:
FetchHeaders.cpp, JSCookie.cpp, Cookie.cpp, and
`src/http_types/ETag.rs`). Removed: `isValidReasonPhrase`,
`isValidAcceptHeaderValue`, `isValidLanguageHeaderValue`,
`isValidUserAgentHeaderValue` (+ the entire `#if USE(GLIB)` block;
`USE(GLIB)` is never defined in Bun), `parseHTTPDate`,
`filenameFromHTTPContentDisposition`, `extractMIMETypeFromMediaType`,
`extractCharsetFromMediaType`, `parseXSSProtectionHeader`,
`extractReasonPhraseFromHTTPStatusLine`, `parseXFrameOptionsHeader`,
`parseStructuredFieldValue`, `parseRange` (both overloads),
`parseContentTypeOptionsHeader`, `parseHTTPHeader`,
`parseHTTPRequestBody`, `isForbiddenHeaderName`, `isForbiddenHeader`,
`isNoCORSSafelistedRequestHeaderName`,
`isPriviledgedNoCORSRequestHeaderName`, `isForbiddenResponseHeaderName`,
`isForbiddenMethod`, `isSimpleHeader`, `isCrossOriginSafeRequestHeader`,
`normalizeHTTPMethod`, `isSafeMethod`,
`parseCrossOriginResourcePolicyHeader`, their 7 static helpers
(`skipWhile`, `skipWhiteSpace`, `skipToken`, `skipEquals`, `skipValue`,
`trimInputSample`, `isValidHeaderNameCharacter`), and the 6 enum types
that only those functions use (`XSSProtectionDisposition`,
`ContentTypeOptionsDisposition`, `XFrameOptionsDisposition`,
`CrossOriginResourcePolicy`, `RangeAllowWhitespace`, `HTTPHeaderSet`).

### `ncrypto.{h,cpp}` (~609 lines removed)

Removed `SSLPointer`, `SSLCtxPointer`, `X509Name` (+
`X509Name::Iterator`), `EnginePointer`,
`StackOfX509`/`StackOfX509Deleter`, `SSLSessionPointer`, and their
dependents (`X509View::From(SSLPointer/SSLCtxPointer)`,
`X509View::getSubjectName/getIssuerName`, `X509Pointer::IssuerFrom` both
overloads, `X509Pointer::PeerFrom`). `rg -wn
'SSLPointer|SSLCtxPointer|EnginePointer|X509Name\b|StackOfX509' src/
build/debug/codegen/` outside ncrypto itself finds nothing. Bun's TLS
goes through usockets/boringssl directly; these ncrypto wrappers were
never wired up. `X509View` and `X509Pointer` themselves stay
(JSX509Certificate uses them).

### Smaller items

- `JSBufferEncodingType.{h,cpp}`: `validateBufferEncoding<bool>()`
template + two explicit specializations, never called (`rg -wn
validateBufferEncoding src/ build/debug/codegen/` finds only the
definitions).
- `src/js/node/dgram.ts`: removed the commented-out
`_createSocketHandle` block; the live implementation is in
`src/js/internal/dgram.ts` and is what
`internal/cluster/SharedHandle.ts` imports.

## Verification

- `rg` for each removed symbol across `src/`, `build/debug/codegen/`,
`src/codegen/`: zero hits outside own definition.
- `bun bd`: builds clean.
- Smoke tests pass: `test/js/web/fetch/headers.test.ts`,
`test/js/node/crypto/crypto.test.ts`,
`test/js/node/crypto/x509.test.ts`,
`test/js/bun/http/bun-serve-cookies.test.ts`,
`test/js/sql/sql-close-pending-connection.test.ts`.
- `test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts`
asserts the removed symbols/files do not reappear.

## Dropped from the original push after CI bisection

The first push also removed `kServerSocket`/`kpendingRead` from
`src/js/node/net.ts`, removed
`m_clients`/`addClient`/`JSVMClientDataClient` from `BunClientData`, and
deleted the four .cpp files outright. That build crashed
`test/js/sql/sql-close-pending-connection.test.ts` and
`test/js/sql/sql.test.ts` on every CI lane with
`RELEASE_ASSERT(m_heap.m_mutatorState == MutatorState::Running)`
(allocation during GC sweep), not reproducible locally on debug+asan or
release. Reverting those three groups clears it; narrowing which one is
the trigger is left for a follow-up since each is ~10 lines.

## Followups (not in this diff)

`patches/ncrypto.patch` (the reference diff for re-deriving
ncrypto.{h,cpp} from upstream Node ncrypto) still contains hunks for
SSLPointer/SSLCtxPointer/X509Name/EnginePointer; it is not applied by
any build step, so it needs regenerating on the next upstream sync.

Emptying `EventDispatcher.cpp` orphans
`EventContext::handleLocalEvents()` (EventContext.h:62 / .cpp:43) and
`Node::defaultEventHandler()` (Node.h:52); left for a follow-up sweep
alongside the rest of the Event*/EventPath cascade rather than widening
this diff mid-CI-bisection.

More dead ncrypto found but left for a focused PR: `#include
<openssl/ssl.h>` at ncrypto.h:23 (orphaned by the
SSLPointer/SSLCtxPointer removal, same class as the engine.h include
dropped here), `setFipsEnabled`/`testFipsEnabled`, `hashDigest`,
`checkScryptParams`/`scrypt`/`pbkdf2`, `Cipher::ForEach`,
`Rsa::encrypt/decrypt`, the unused `Cipher::AES_*_CTR/GCM/KW` getters,
`DataPointer::TryInitSecureHeap/SecureAlloc/GetSecureHeapUsed`,
`EVPKeyCtxPointer::setRsaImplicitRejection/publicCheck/privateCheck`,
`X509View::enumUsages/ifRsa/ifEc`, `X509Pointer::ErrorReason`,
`BIOPointer::NewSecMem/NewFile/NewFp`, `BignumPointer::NewSub/NewLShift`
(~300 lines).

Also found but overlap with open dead-code PRs so left alone:
`headers-cpp.h`/`sizegen.cpp` (tangled with #36115),
`objects.h`/`TextCodecASCIIFastPath.h`/`ZigLazyStaticFunctions*.h`
(#35437), `JSCInlines.h` (#36237), `EventSender.h` (#35775).

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 2 · 57 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 5 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts
bun test v1.4.0 (4fba9c1)

test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts:
53 |           const t = l.trim();
54 |           return t !== "" && !t.startsWith("//") && t !== allowed;
55 |         });
56 |     })
57 |     .map(([p]) => p);
58 |   expect(nonStub).toEqual([]);
                       ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/EventDispatcher.h",
+   "src/jsc/bindings/webcore/EventModifierInit.h",
+   "src/jsc/bindings/webcore/JSEventModifierInit.h",
+   "src/jsc/bindings/webcore/UIEventInit.h",
+   "src/jsc/bindings/webcore/EventDispatcher.cpp",
+   "src/jsc/bindings/webcore/JSEventModifierInit.cpp",
+   "src/jsc/bindings/ncrpyto_engine.cpp",
+ ]

- Expected  - 1
+ Received  + 9

      at <anonymous> (/workspace/bun/test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts:58:19)
(fail) emptied dead C++ files stay empty [47.32ms]
78 |     ["src/jsc/bindings/webcore/HTTPParsers.cpp", /
... (truncated)

release without fix: 5 FAILED
bun test v1.4.0-canary.1 (5cea549)

test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts:
53 |           const t = l.trim();
54 |           return t !== "" && !t.startsWith("//") && t !== allowed;
55 |         });
56 |     })
57 |     .map(([p]) => p);
58 |   expect(nonStub).toEqual([]);
                       ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/EventDispatcher.h",
+   "src/jsc/bindings/webcore/EventModifierInit.h",
+   "src/jsc/bindings/webcore/JSEventModifierInit.h",
+   "src/jsc/bindings/webcore/UIEventInit.h",
+   "src/jsc/bindings/webcore/EventDispatcher.cpp",
+   "src/jsc/bindings/webcore/JSEventModifierInit.cpp",
+   "src/jsc/bindings/ncrpyto_engine.cpp",
+ ]

- Expected  - 1
+ Received  + 9

      at <anonymous> (/workspace/bun/test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts:58:19)
(fail) emptied dead C++ files stay empty [1.13ms]
78 |     ["src/jsc/bindings/webcore/HTTPParsers.cpp", /\bisCrossOriginSafeRequestHeader\b/],
79 |     ["src/jsc/bindings/webcore/HTTPParsers.cpp", /\bnormalizeHTTPMethod\b/],
80 |     ["src/jsc/bindings/webcore/HTTPParsers.cpp", /\bparseXFrameOptio
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts
bun test v1.4.0 (4fba9c1)

test/internal/source-lints/dead-symbols-httpparsers-ncrypto.test.ts:
(pass) emptied dead C++ files stay empty [19.36ms]
(pass) dead HTTPParsers functions do not reappear [20.51ms]
(pass) dead ncrypto SSL/Engine/X509Name wrappers do not reappear [16.23ms]
(pass) dead misc C++ symbols do not reappear [8.75ms]
(pass) dead src/js symbols do not reappear [2.81ms]

 5 pass
 0 fail
 5 expect() calls
Ran 5 tests across 1 file. [2.20s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 640ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[0/1] reconfigure
[1/104] gen JSEvent.lut.h
Generating /workspace/bun/build/release/codegen/JSEvent.lut.h from /workspace/bun/src/jsc/bindings/webcore/JSEvent.cpp
[2/104] gen JSBuffer.lut.h
Generating /workspace/bun/build/release/codegen/JSBuffer.lut.h from /workspace/bun/src/jsc/bindings/JSBuffer.cpp
[3/104] gen cpp.rs (cppbind)
[4/104] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 6 sinks, 72 exported symbols
Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt
[5/104] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 239 extern-C blocks audited
[6/104] gen JS modules (bundle-modules)
Preprocess modules (10243ms)
Bundle modules (49ms)
Postprocesss modules (196ms)
Bundle Functions (855ms)
Generate Code (36ms)

[11.40s] Bundled "src/js" for production
  2569 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[6/103] cargo bun_bin → libbun_rust.a (
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
scripts/build/unified.ts                           |   2 +
 src/codegen/generate-jssink.ts                     |   1 -
 src/js/node/dgram.ts                               |  41 -
 src/jsc/bindings/DOMURL.cpp                        |   1 -
 src/jsc/bindings/ImportMetaObject.cpp              |   1 -
 src/jsc/bindings/JSBuffer.cpp                      |   1 -
 src/jsc/bindings/JSBufferEncodingType.cpp          |  26 -
 src/jsc/bindings/JSBufferEncodingType.h            |   3 -
 src/jsc/bindings/ScriptExecutionContext.h          |   1 -
 src/jsc/bindings/ncrpyto_engine.cpp                | 108 +--
 src/jsc/bindings/ncrypto.cpp                       | 431 ----------
 src/jsc/bindings/ncrypto.h                         | 181 -----
 src/jsc/bindings/webcore/ActiveDOMObject.cpp       | 197 +----
 src/jsc/bindings/webcore/ActiveDOMObject.h         | 172 +---
 src/jsc/bindings/webcore/EventDispatcher.cpp       | 239 +-----
 src/jsc/bindings/webcore/EventDispatcher.h         |  41 +-
 src/jsc/bindings/webcore/EventModifierInit.h       |  42 +-
 src/jsc/bindings/webcore/HTTPParsers.cpp           | 884 ---------------------
 src/jsc/bindings/webcore/HTTPParsers.h             | 128 ---
 src/jsc/bindings/webcore/JSAbortController.cpp     |   1 -
 src/jsc/bindings/webcore/JSAbortSignal.cpp         |   1 -
 src/jsc/bindings/webcore/JSBroadcastChannel.cpp    |   1 -
 src/jsc/bindings/webcore/JSCloseEvent.cpp          |   1 -
 src/jsc/bindings/webcore/JSCustomEvent.cpp         |   1 -
 src/jsc/bindings/webcore/JSDOMException.cpp        |   1 -
 src/jsc/bindings/webcore/JSDOMFormData.cpp         |   1 -
 src/jsc/bindings/webcore/JSDOMURL.cpp              |   1 -
 src/jsc/bindings/webcore/JSErrorEvent.cpp          |   1 -
 src/jsc/bindings/webcore/JSEvent.cpp               |   1 -
 src/jsc/bindings/webcore/JSEventEmitter.cpp        |   1 -
 src/jsc/bindings/webcore/JSEventModifierInit.cpp   | 180 +----
 src/jsc/bindings/webcore/JSEventModifierInit.h     |  30 +-
 src/jsc/
... (truncated)
```

</details>

**gate history** · 1 passed · 2 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                          reads  edits  tests
scripts/build/unified.ts                          1      1      0
src/codegen/generate-jssink.ts                    0      0      0
src/js/node/dgram.ts                              1      1      0
src/jsc/bindings/DOMURL.cpp                       0      0      0
src/jsc/bindings/ImportMetaObject.cpp             0      0      0
src/jsc/bindings/JSBuffer.cpp                     0      0      0
src/jsc/bindings/JSBufferEncodingType.cpp         2      3      0
src/jsc/bindings/JSBufferEncodingType.h           1      1      0
src/jsc/bindings/ScriptExecutionContext.h         0      0      0
src/jsc/bindings/ncrpyto_engine.cpp               0      4      0
src/jsc/bindings/ncrypto.cpp                      2      6      0
src/jsc/bindings/ncrypto.h                        5      8      0
src/jsc/bindings/webcore/ActiveDOMObject.cpp      0      3      0
src/jsc/bindings/webcore/ActiveDOMObject.h        1      3      0
src/jsc/bindings/webcore/EventDispatcher.cpp      0      4      0
src/jsc/bindings/webcore/EventDispatcher.h        1      3      0
(+ 41 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
Jarred-Sumner pushed a commit that referenced this pull request Aug 1, 2026
…n_jsc Rust (#36576)

Net **-1185 lines** (+68 / -1253) across 24 files. Every removed item
was verified to have zero references across `src/` and
`build/debug/codegen/`, then confirmed by a full `bun bd` build and `bun
run rust:check-all`.

No overlap with the 11 open dead-code PRs (checked file lists of #34965
#34759 #36474 #36178 #36237 #35559 #35775 #36318 #36115 #35437 #35880).

### Whole-file deletions (C++, 1107 lines)

| File | LOC | Verification |
|---|---|---|
| `src/jsc/bindings/node/http/llhttp/api.h` | 357 | Never `#include`d.
Vendored upstream copy artifact; all 41 `LLHTTP_EXPORT` decls are
duplicated verbatim in `llhttp.h`, and `api.c` includes `llhttp.h` not
`api.h`. Only mentioned in `llhttp/README.md`. |
| `src/jsc/bindings/webcore/JSDOMConvertWebGL.{h,cpp}` | 317 | Entire
body guarded by `#if ENABLE(WEBGL)`. The .cpp `#include`s ~40 headers
(`JSANGLEInstancedArrays.h` etc.) that don't exist in the repo, so the
guard is provably inactive on every bun target.
`IDLWebGLAny`/`IDLWebGLExtension` used nowhere else. |
| `src/jsc/bindings/headers-cpp.h` | 190 | Only includer is
`headergen/sizegen.cpp`, which isn't in any build rule. File itself has
syntax errors (line 166 `#include ""ConsoleObject.h""`, lines 172-182
`#include ""`), so it cannot be compiling anywhere. |
| `src/jsc/bindings/webcore/HTTPHeaderValues.{h,cpp}` | 108 | Header
only included by its own .cpp; none of the five declared functions
(`textPlainContentType`, `formURLEncodedContentType`,
`applicationJSONContentType`, `noCache`, `maxAge0`) are called anywhere.
|
| `src/jsc/bindings/webcore/JSDOMConvertJSON.h` | 51 | Sole includer is
the umbrella `JSDOMConvert.h`. `IDLJSON` is referenced nowhere outside
`IDLTypes.h` (type decl) and this file. |
| `src/jsc/bindings/ares_build.h` | 42 | Zero `#include`s anywhere under
`src/`. Superseded by the generated
`build/<profile>/deps/cares/ares_build.h` emitted by
`scripts/build/deps/cares.ts`. |
| `src/jsc/bindings/webcore/TaskSource.h` | 29 | Never `#include`d. Only
referenced in commented-out code in `WebSocket.cpp` /
`JSDOMPromiseDeferred.cpp`. |
| `src/jsc/bindings/JSVMClientDataClient.h` | 13 | See `BunClientData`
below. |

### C++ symbol removals

- **`helpers.h`** (38 lines): `Zig::toAtomString(ZigString)`,
`toStringNotConst`, `__dot_char`/`ZigStringCwd`/`BunStringCwd`,
`toZigString(WTF::String*)`, `toZigString(JSC::Identifier&)` +
`(JSC::Identifier*)`, `Zig::toStringView(ZigString)`. rg across src/ and
codegen shows zero callers for each.
- **`headers-handwritten.h`** (22 lines): `WritableEvent` typedef + 8
consts, `ReadableEvent` typedef + 9 consts. Zero references anywhere.
- **`JSDOMWrapper.h`** (8 lines): `JSTextNodeType`,
`JSProcessingInstructionNodeType`, `JSDocumentTypeNodeType`,
`JSDocumentFragmentNodeType`, `JSDocumentWrapperType`,
`JSCommentNodeType`, `JSCDATASectionNodeType`, `JSAttrNodeType`. Only
referenced in commented-out code at `webcore/DOMJITHelpers.h:163-178`.
(`JSNodeType`/`JSNodeTypeMask`/`JSElementType`/`JSAsJSONType` kept.)
- **`BunClientData.{h,cpp}`** (9 lines): `addClient()` is never called,
so `m_clients` is always empty and the `~JSVMClientData`
`forEach`/`clear` loop is a no-op. Removed `addClient`, `m_clients`, the
dtor loop, and the include of `JSVMClientDataClient.h`.
- **`JSDOMConvert.h`** (2 lines): removed `#include` of the two deleted
headers.
- **`headergen/sizegen.cpp`** (2 lines): removed `#include
"headers-cpp.h"`. The file is not in any build rule and was already
uncompilable (its loop references `names[]`/`sizes[]`/`aligns[]`, none
of which were ever fully defined); leaving the loop untouched to
minimise conflict with #36115..

### Rust removals

- **`bun_core::String::github_action` + `StringGithubActionFormatter`**
(22 lines): all four `.github_action()` call sites in
`VirtualMachine.rs` are on `jsc::ZigString`, not `bun_core::String`. The
`ZigString` variant is kept.
- **`bun_jsc::JSUint8Array::ptr()` +
`sizes::BUN_FFI_POINTER_OFFSET_TO_TYPED_ARRAY_VECTOR`** (14 lines): zero
callers.
- **`bun_jsc::RefString::to_js()`** (9 lines): the sole external
`RefString` user (`filesystem_router.rs`) never calls `.to_js()`.
Removed along with now-unused
`JSGlobalObject`/`JSValue`/`JsResult`/`StringJsc` imports.
- **`bun_jsc::Errorable::value()`** (7 lines): identical body to
`Errorable::ok()`; every caller uses `ok()`.

### Verification

- `bun bd` passes
- `bun run rust:check-all` passes on all targets
- `bun bd test test/internal/source-lints/` passes (62 tests)
- `bun bd test test/js/node/inspector/` passes (67 tests; exercises
`BunDebugger.cpp`)
- `bun bd test test/cli/install/bun-install-lifecycle-scripts.test.ts`
passes (3 pre-existing env failures unrelated to this diff, reproduced
on main)

### Followups (not in this diff)

- `src/jsc/bindings/CachedScript.h` is semantically vestigial (empty
class, all callers pass `nullptr`) but removing it requires editing
signatures in `ScriptExecutionContext.h` /
`JSDOMExceptionHandling.{h,cpp}`.
- `src/ast/lib.rs` `StringBuilder` stub + the `count()` method chain is
a no-op cluster but removing it requires dropping the `&mut
StringBuilder` parameter from three `clone_with_builder` signatures.
- `src/runtime/api/bun/h2/connection.rs`
`send_header_block`/`send_push_promise`/`send_data`/`encode_header`/`begin_header_block`
(~173 LOC) are only called from `#[cfg(test)]`; intentionally staged per
the `h2/mod.rs` module doc for a future rewrite, so left alone.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 2 · 24 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 2 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-llhttp-helpers-install.test.ts
bun test v1.4.0 (6057ada)

test/internal/source-lints/dead-symbols-llhttp-helpers-install.test.ts:
50 |     ["src/jsc/bindings/webcore/JSDOMConvert.h", /JSDOMConvertWebGL\.h/],
51 |     ["src/jsc/bindings/IDLTypes.h", /\bIDLJSON\b/],
52 |     ["src/jsc/headergen/sizegen.cpp", /headers-cpp\.h/],
53 |   ];
54 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
55 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/helpers.h: static WTF::AtomString toAtomString\(ZigString",
+   "src/jsc/bindings/helpers.h: \btoStringNotConst\b",
+   "src/jsc/bindings/helpers.h: \b__dot_char\b",
+   "src/jsc/bindings/helpers.h: \bZigStringCwd\b",
+   "src/jsc/bindings/helpers.h: \bBunStringCwd\b",
+   "src/jsc/bindings/helpers.h: toZigString\(WTF::String\*",
+   "src/jsc/bindings/helpers.h: toZigString\(JSC::Identifier&",
+   "src/
... (truncated)

release without fix: 2 FAILED
bun test v1.4.0-canary.1 (91f57fe)

test/internal/source-lints/dead-symbols-llhttp-helpers-install.test.ts:
50 |     ["src/jsc/bindings/webcore/JSDOMConvert.h", /JSDOMConvertWebGL\.h/],
51 |     ["src/jsc/bindings/IDLTypes.h", /\bIDLJSON\b/],
52 |     ["src/jsc/headergen/sizegen.cpp", /headers-cpp\.h/],
53 |   ];
54 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
55 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/helpers.h: static WTF::AtomString toAtomString\(ZigString",
+   "src/jsc/bindings/helpers.h: \btoStringNotConst\b",
+   "src/jsc/bindings/helpers.h: \b__dot_char\b",
+   "src/jsc/bindings/helpers.h: \bZigStringCwd\b",
+   "src/jsc/bindings/helpers.h: \bBunStringCwd\b",
+   "src/jsc/bindings/helpers.h: toZigString\(WTF::String\*",
+   "src/jsc/bindings/helpers.h: toZigString\(JSC::Identifier&",
+   "src/jsc/bindings/helpers.h: toZigString\(JSC::Identifier\*",
+   "src/jsc/bindings/helpers.h: static WTF::StringView toStringView\(ZigString",
+   "src/jsc/bindings/headers-handwritten.h: \bWritableE
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-llhttp-helpers-install.test.ts
bun test v1.4.0 (6057ada)

test/internal/source-lints/dead-symbols-llhttp-helpers-install.test.ts:
(pass) dead C++ symbols in helpers.h / headers-handwritten.h / JSDOMWrapper.h / BunClientData do not reappear [37.66ms]
(pass) dead Rust symbols in bun_core / jsc do not reappear [9.99ms]

 2 pass
 0 fail
 2 expect() calls
Ran 2 tests across 1 file. [2.03s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 647ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/122] gen cpp.rs (cppbind)
[2/122] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 239 extern-C blocks audited
[3/122] gen JS modules (bundle-modules)
Preprocess modules (8812ms)
Bundle modules (38ms)
Postprocesss modules (34ms)
Bundle Functions (748ms)
Generate Code (19ms)

[9.67s] Bundled "src/js" for production
  2569 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[3/121] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

�[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
�[1m�[92m   Compiling�[0m bun_errno v0.0.0 (/workspace/bun/src/errno)
�[1m�[92m   Compiling�[0m bun_ptr v0.0.0 (/workspace/bun/src/ptr)
�[1m�[92m   Compiling�[0m bun_boringssl_sys v0.0.0 (/workspace/bun/src/boringssl_sys)
�[1m�[92m   Compiling�[0m bun_safety v0.0.0 (/workspace/bun/src/safety)
�[1m�
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/bun_core/string/mod.rs                         |  22 --
 src/jsc/Errorable.rs                               |   7 -
 src/jsc/JSUint8Array.rs                            |  13 -
 src/jsc/RefString.rs                               |   9 -
 src/jsc/bindings/BunClientData.cpp                 |   5 -
 src/jsc/bindings/BunClientData.h                   |   5 -
 src/jsc/bindings/IDLTypes.h                        |  12 -
 src/jsc/bindings/JSDOMWrapper.h                    |   8 -
 src/jsc/bindings/JSVMClientDataClient.h            |  13 -
 src/jsc/bindings/ares_build.h                      |  42 ---
 src/jsc/bindings/headers-cpp.h                     | 190 -----------
 src/jsc/bindings/headers-handwritten.h             |  22 --
 src/jsc/bindings/helpers.h                         |  38 ---
 src/jsc/bindings/node/http/llhttp/api.h            | 357 ---------------------
 src/jsc/bindings/webcore/HTTPHeaderValues.cpp      |  68 ----
 src/jsc/bindings/webcore/HTTPHeaderValues.h        |  40 ---
 src/jsc/bindings/webcore/JSDOMConvert.h            |   2 -
 src/jsc/bindings/webcore/JSDOMConvertJSON.h        |  51 ---
 src/jsc/bindings/webcore/JSDOMConvertWebGL.cpp     | 249 --------------
 src/jsc/bindings/webcore/JSDOMConvertWebGL.h       |  68 ----
 src/jsc/bindings/webcore/TaskSource.h              |  29 --
 src/jsc/headergen/sizegen.cpp                      |   2 -
 src/jsc/sizes.rs                                   |   1 -
 .../dead-symbols-llhttp-helpers-install.test.ts    |  68 ++++
 24 files changed, 68 insertions(+), 1253 deletions(-)
```

</details>

**gate history** · 1 passed · 1 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                           reads  edits  tests
src/bun_core/string/mod.rs                         1      2      0
src/jsc/Errorable.rs                               1      1      0
src/jsc/JSUint8Array.rs                            1      2      0
src/jsc/RefString.rs                               2      2      0
src/jsc/bindings/BunClientData.cpp                 1      1      0
src/jsc/bindings/BunClientData.h                   2      2      0
src/jsc/bindings/IDLTypes.h                        1      1      0
src/jsc/bindings/JSDOMWrapper.h                    1      1      0
src/jsc/bindings/JSVMClientDataClient.h            0      0      0
src/jsc/bindings/ares_build.h                      0      0      0
src/jsc/bindings/headers-cpp.h                     0      0      0
src/jsc/bindings/headers-handwritten.h             1      1      0
src/jsc/bindings/helpers.h                         2      2      0
src/jsc/bindings/node/http/llhttp/api.h            0      0      0
src/jsc/bindings/webcore/HTTPHeaderValues.cpp      0      0      0
src/jsc/bindings/webcore/HTTPHeaderValues.h        0      0      0
(+ 8 more files)
```

</details>

<!-- robobun:evidence:end -->
Jarred-Sumner added a commit that referenced this pull request Aug 1, 2026
…JSDOMConvert*, rescle, wasi (#36474)

Net: **-3673 LOC** (30 files, +177 / -3850). No behavior change.

Nothing here overlaps with the other open dead-code PRs (#34965, #34759,
#36426, #36178, #36237, #35775, #35559, #36318, #36115, #35437, #35880);
every touched file was checked against their file lists.

### SerializedScriptValue.cpp / .h (7239 → 5090, 413 → 202)

- All `#if ENABLE(OFFSCREEN_CANVAS_IN_WORKERS)`, `#if ENABLE(WEB_RTC)`,
`#if ENABLE(WEB_CODECS)`, `#if
ENABLE(PREDEFINED_COLOR_SPACE_DISPLAY_P3)` blocks. Bun's JSCOnly
`cmakeconfig.h` sets all four to 0 on every target, and the referenced
types (`OffscreenCanvas`, `RTCCertificate`, `DetachedRTCDataChannel`,
`WebCodecsVideoFrame`, ...) have no headers anywhere under `src/`, so
the guarded bodies could not compile if the macros flipped.
- ~1200 lines of long-commented-out serialization paths for DOM geometry
(`DOMPoint`/`DOMRect`/`DOMMatrix`/`DOMQuad`), `ImageBitmap`,
`File`/`FileList`, `Blob`, `ImageData`, blob-URL/IDB helpers, and
alternate ctors. All date to 2022.
- Uncalled public methods (`rg` across `src/` and
`build/debug/codegen/`): `create(StringView)`, `create(JSContextRef,
JSValueRef, JSValueRef*)`, `deserialize(JSContextRef, JSValueRef*)`,
`toString()`, `nullValue()`, `wireFormatVersion()`, and the
never-instantiated `encode<Encoder>()` / `decode<Decoder>()` templates.
Plus their private-only helpers `CloneSerializer::serialize(StringView,
Vector<uint8_t>&)`, `CloneDeserializer::deserializeString()`,
`blobFilePathForBlobURL()`, `wrapCryptoKey()`, `unwrapCryptoKey()`,
`write/read(DestinationColorSpaceTag)`, the `PLATFORM(COCOA)`
`CFDataRef` helpers, and the `fillTransferMap(const Vector<Ref<T>>&,
...)` overload.
- Orphaned enums `PredefinedColorSpaceTag`, `DestinationColorSpaceTag`,
`ImageDataPoolTag`, `m_transferredImageBitmaps`, and 18
`SerializationTag` values that are no longer written or read in live
code (`FileTag`, `FileListTag`, `ImageDataTag`, `BlobTag`,
`DOMPoint*/Rect*/Matrix*/QuadTag`, `ImageBitmap*Tag`,
`OffscreenCanvasTransferTag`, `RTC*Tag`, `WebCodecs*Tag`). The
grammar-comment documentation block is kept.

Followup note: `m_blobURLs` / `m_blobFilePaths` are now write-only
(their sole reader `blobFilePathForBlobURL` is gone), but removing them
cascades through the live `CloneDeserializer` ctor params and the public
`deserialize(..., blobURLs, blobFilePaths, ...)` overload. Left as-is.

### WebSocket.cpp / .h (-212)

- Uncalled `create(ctx, url, protocols, headers, bool)` 5-arg overload
and the three `connect(const String&[, ...])` overloads (all
`JSWebSocket.cpp` paths use the 2/3/8/9-arg `create` and the 4-arg
`connect`).
- `didUpdateBufferedAmount(unsigned)`, the decl-only
`didReceiveData(const char*, size_t)` and
`WebSocket(ScriptExecutionContext&, const String&)`, and the uncalled
`offerPerMessageDeflate()` getter.
- 2022-era commented-out blocks: CSP/portAllowed,
`ResourceLoadObserver`/`MixedContentChecker`,
`ENABLE(INTELLIGENT_TRACKING_PREVENTION)`,
`contextDestroyed`/`suspend`/`resume`/`stop`/`activeDOMObjectName`, four
`ConnectedWebSocketKind::Server` case blocks, and the commented
`#include`s.
- `m_dispatchedErrorEvent` (only read by the removed `suspend`/`resume`
block).

### JSDOMConvert{Sequences,Strings,Record,Union}.h / .cpp (-381)

- `NumericSequenceConverter` and the five
`SequenceConverter<IDL{Long,Float,UnrestrictedFloat,Double,UnrestrictedDouble}>`
specializations. `IDLSequence<T>` is only instantiated with string /
enum / interface / dictionary / object element types in Bun (`rg
'IDLSequence<IDL(Long|Float|Double|Unrestricted)' src/
build/debug/codegen/` = 0).
- `Converter<IDLFrozenArray<T>>` (only the `JSConverter` side is used),
`JSConverter<IDLRecord<K,V>>` (only the `Converter` side is used), and
the `IDLAllowSharedAdaptor<IDLUnion<IDLArrayBufferView,
IDLArrayBuffer>>` specs (webcrypto uses the un-wrapped union).
- `propertyNameToString` / `propertyNameToAtomString`, the
`IDLLegacyNullToEmpty{,Atom}StringAdaptor` and
`IDLAtomStringAdaptor<IDL{USV,Byte}String>` converters, and
`valueToByteAtomString` / `valueToUSVAtomString` (their only callers).

### windows/rescle.cpp / .h (-278)

The only entry point `rescle__setWindowsMetadata` (from
`src/sys/windows/mod.rs`) uses `Load`, `SetIcon`, `SetVersionString`,
`SetFileVersion`, `SetProductVersion`, `Commit`. Removed
`SetExecutionLevel`, `IsExecutionLevelSet`, `SetApplicationManifest`,
`IsApplicationManifestSet`, `GetVersionString`×2, `ChangeString`×2,
`ChangeRcData`, `GetString`×2, `OnEnumResourceManifest` + its `Load()`
registration, the now-always-false execution-level and manifest branches
in `Commit()`, `ReadFileToString`, the
`executionLevel_`/`originalExecutionLevel_`/`applicationManifestPath_`/`manifestString_`
members, and five unused `RU_VS_*` macros.

Followup note: with `ChangeString`/`ChangeRcData` gone,
`stringTableMap_` and `rcDataLngMap_` are now populated by `Load()` and
written back unchanged by `Commit()`. That round-trip was already a
semantic no-op on `main` (the removed mutators had zero callers there
too), but removing it touches a live Windows `bun build --compile` path
rather than an unreferenced helper, so it is deferred rather than folded
into this sweep.

### Performance.cpp / .h + PerformanceObserver.h (-154)

- `addResourceTiming(ResourceTiming&&)` (no callers; Bun's fetch
produces `PerformanceResourceTiming` via `queueEntry` directly),
`isResourceTimingBufferFull()`, `m_backupResourceTimingBuffer`,
`m_waitingForBackupBufferToBeProcessed`.
- `allowHighPrecisionTime()` + `highTimePrecision`, `timeResolution()`,
`relativeTimeFromTimeOriginInReducedResolution(MonotonicTime)` (no
callers).
- 2024-era commented-out `navigation()`,
`reportFirstContentfulPaint`/`addNavigationTiming`/`navigationFinished`,
`resourceTimingBufferFullTimerFired()`.
- `PerformanceObserver.h`:
`hasNavigationTiming`/`addedNavigationTiming`/`m_hasNavigationTiming`
(only referenced from the commented-out code above).

### EventTarget.cpp / .h + EventListenerMap (-51)

- `isPaymentRequest()` virtual (no callers, no overriders).
- `legacyType(const Event&)` static, which unconditionally returned
`nullAtom()` since 2022, and the legacy-fallback block in
`fireEventListeners` it made unreachable.
- `hasCapturingEventListeners(const AtomString&)` (no callers) and its
only callee `EventListenerMap::containsCapturing`.
- Decl-only `invalidateJSEventListeners(JSC::JSObject*)`.

### src/js/node/wasi.ts (-280)

- The four `exports.X = exports.Y = ... = void 0;` pre-declaration
chains (186 LOC). These are tsc emit artifacts from the original
`wasi-js` npm bundle; every property is re-assigned to its real value
immediately after.
- `WASIExitError` / `WASIKillError` classes (the `types` module is only
consumed as `types_1.WASIError`).
- `exports.SOCKET_DEFAULT_RIGHTS` (written once, never read).
- `initWasiFdInfo()` (never called; contains five debug `console.log`
calls).
- `if (log.enabled) { ... }` blocks and bare `log(...)` / `logOpen(...)`
calls (`log` is hard-coded to `() => {}` and never reassigned).

### src/js/thirdparty/ws.js (-19)

- Long-commented-out `secWebSocketExtensions` / `PerMessageDeflate`
block (May 2023).

### Rust (-22)

- `bun_http`: `PRINT_EVERY` / `PRINT_EVERY_I` debug scaffolding and the
`if PRINT_EVERY != 0 { ... }` block it made always-dead.
- `bun_threading`: drop `GuardedBy`, `RawMutex`, `RwLockReadGuard`,
`RwLockWriteGuard` from the crate re-export list (zero
`bun_threading::X` references; the backing types stay for `Guarded`'s
impl).
- `bun_standalone_graph`: `Error::UnsupportedTarget` variant (never
constructed; `download_to_path` returns other variants).
- `bun_bunfig`: the unused `OfflineMode` re-export.

### Verification

- `rg -w <symbol> src/ build/debug/codegen/ src/codegen/` returned only
the definition for each deleted item.
- `bun bd` builds clean.
- `bun run rust:check-all` passes on all 10 targets (linux/macos/windows
× x64/aarch64, plus musl).
- Smoke tests pass: `structured-clone.test.ts` (231/231),
`structuredClone-classes.test.ts`, `worker_threads.test.ts` (91/91),
`websocket-client.test.ts`, `abort.test.ts`,
`performance-entries.test.ts`, `wasi.test.js`,
`deno/event/event-target.test.ts`.
- New `test/internal/source-lints/dead-symbols-ssv-wasi-webcore.test.ts`
guards against reintroduction: fails (7/7) with `src/` at `main`, passes
(7/7) with this diff.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 1 · 30 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 7 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-ssv-wasi-webcore.test.ts
bun test v1.4.0 (e0122fc)

test/internal/source-lints/dead-symbols-ssv-wasi-webcore.test.ts:
47 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /static Ref<SerializedScriptValue> nullValue\(\)/],
48 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /static uint32_t wireFormatVersion\(\)/],
49 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /void encode\(Encoder&\) const/],
50 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /static RefPtr<SerializedScriptValue> decode\(Decoder&/],
51 |   ];
52 |   expect(resurrected(checks)).toEqual([]);
                                   ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: ENABLE\(OFFSCREEN_CANVAS_IN_WORKERS\)",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: ENABLE\(WEB_RTC\)",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: ENABLE\(WEB_CODECS\)",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp:
... (truncated)

release without fix: 7 FAILED
bun test v1.4.0-canary.1 (754b4fe)

test/internal/source-lints/dead-symbols-ssv-wasi-webcore.test.ts:
47 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /static Ref<SerializedScriptValue> nullValue\(\)/],
48 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /static uint32_t wireFormatVersion\(\)/],
49 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /void encode\(Encoder&\) const/],
50 |     ["src/jsc/bindings/webcore/SerializedScriptValue.h", /static RefPtr<SerializedScriptValue> decode\(Decoder&/],
51 |   ];
52 |   expect(resurrected(checks)).toEqual([]);
                                   ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: ENABLE\(OFFSCREEN_CANVAS_IN_WORKERS\)",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: ENABLE\(WEB_RTC\)",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: ENABLE\(WEB_CODECS\)",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: readRTCCertificate",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: readOffscreenCanvas",
+   "src/jsc/bindings/webcore/SerializedScriptValue.cpp: readWebCodecsVideoFrame",
+   "
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-ssv-wasi-webcore.test.ts
bun test v1.4.0 (e0122fc)

test/internal/source-lints/dead-symbols-ssv-wasi-webcore.test.ts:
(pass) dead SerializedScriptValue ENABLE() blocks and unused public methods do not reappear [71.54ms]
(pass) dead WebSocket create/connect overloads and commented-out WebKit blocks do not reappear [23.13ms]
(pass) dead Performance/PerformanceObserver/EventTarget members do not reappear [22.29ms]
(pass) dead JSDOMConvert* template specializations do not reappear [16.77ms]
(pass) dead windows/rescle.cpp resource-editing methods do not reappear [19.33ms]
(pass) dead wasi.ts bundle artifacts and debug scaffolding do not reappear [14.77ms]
(pass) dead Rust http/threading/standalone_graph/bunfig items do not reappear [8.79ms]

 7 pass
 0 fail
 7 expect() calls
Ran 7 tests across 1 file. [2.27s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 718ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/138] gen ErrorCode+*.h
[2/138] gen bake.{client,server,error}.js
-> bake.client.js, bake.server.js, bake.error.js
[3/138] gen JSEvent.lut.h
Generating /workspace/bun/build/release/codegen/JSEvent.lut.h from /workspace/bun/src/jsc/bindings/webcore/JSEvent.cpp
[4/138] gen JSBuffer.lut.h
Generating /workspace/bun/build/release/codegen/JSBuffer.lut.h from /workspace/bun/src/jsc/bindings/JSBuffer.cpp
[5/138] gen cpp.rs (cppbind)
[6/138] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 6 sinks, 72 exported symbols
Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt
[7/138] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 239 extern-C blocks audited
[8/138] gen JS modules (bundle-modules)
Preprocess modules (9054ms)
Bundle modules (45ms)
Postprocesss modules (217ms)
Bundle Functions (732ms)
Generate Code (35ms)

[10.10s] Bundled "src/js" for production
  2561 kb
  193 internal modules
  1
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/bunfig/bunfig.rs                               |    2 -
 src/http/lib.rs                                    |   12 -
 src/js/node/wasi.ts                                |  282 +--
 src/js/thirdparty/ws.js                            |   19 -
 src/jsc/bindings/IDLTypes.h                        |    8 -
 src/jsc/bindings/webcore/Event.h                   |    1 -
 src/jsc/bindings/webcore/EventListenerMap.cpp      |   13 -
 src/jsc/bindings/webcore/EventListenerMap.h        |    1 -
 src/jsc/bindings/webcore/EventTarget.cpp           |   29 +-
 src/jsc/bindings/webcore/EventTarget.h             |    9 -
 src/jsc/bindings/webcore/JSDOMConvertNumbers.h     |   30 -
 src/jsc/bindings/webcore/JSDOMConvertRecord.h      |   31 -
 src/jsc/bindings/webcore/JSDOMConvertSequences.h   |  209 --
 src/jsc/bindings/webcore/JSDOMConvertStrings.cpp   |   25 -
 src/jsc/bindings/webcore/JSDOMConvertStrings.h     |   95 -
 src/jsc/bindings/webcore/JSDOMConvertUnion.h       |   21 -
 src/jsc/bindings/webcore/Performance.cpp           |  165 +-
 src/jsc/bindings/webcore/Performance.h             |   27 +-
 src/jsc/bindings/webcore/PerformanceObserver.cpp   |    2 +-
 src/jsc/bindings/webcore/PerformanceObserver.h     |    4 -
 src/jsc/bindings/webcore/SerializedScriptValue.cpp | 2163 +-------------------
 src/jsc/bindings/webcore/SerializedScriptValue.h   |  213 +-
 src/jsc/bindings/webcore/WebSocket.cpp             |  197 --
 src/jsc/bindings/webcore/WebSocket.h               |   15 -
 src/jsc/bindings/windows/rescle.cpp                |  261 ---
 src/jsc/bindings/windows/rescle.h                  |   21 -
 src/standalone_graph/StandaloneModuleGraph.rs      |    4 -
 src/standalone_graph/error.rs                      |    3 -
 src/threading/lib.rs                               |    5 +-
 .../dead-symbols-ssv-wasi-webcore.test.ts          |  160 ++
 30 files changed, 177 insertions(+), 3850 deletions(-)
```

</details>

**gate history** · 7 passed · 0 rejected · iteration 1

<details><summary>evidence per changed file</summary>

```
file                                              reads  edits  tests
src/bunfig/bunfig.rs                                  0      0      0
src/http/lib.rs                                       0      0      0
src/js/node/wasi.ts                                   0      0      0
src/js/thirdparty/ws.js                               0      0      0
src/jsc/bindings/IDLTypes.h                           1      1      0
src/jsc/bindings/webcore/Event.h                      1      1      0
src/jsc/bindings/webcore/EventListenerMap.cpp         1      1      0
src/jsc/bindings/webcore/EventListenerMap.h           1      1      0
src/jsc/bindings/webcore/EventTarget.cpp              0      0      0
src/jsc/bindings/webcore/EventTarget.h                0      0      0
src/jsc/bindings/webcore/JSDOMConvertNumbers.h        2      1      0
src/jsc/bindings/webcore/JSDOMConvertRecord.h         0      0      0
src/jsc/bindings/webcore/JSDOMConvertSequences.h      0      0      0
src/jsc/bindings/webcore/JSDOMConvertStrings.cpp      0      0      0
src/jsc/bindings/webcore/JSDOMConvertStrings.h        0      0      0
src/jsc/bindings/webcore/JSDOMConvertUnion.h          0      0      0
(+ 14 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
Jarred-Sumner added a commit that referenced this pull request Aug 2, 2026
…C++ bindings (#36756)

Removes 741 net LOC of unreferenced C++ from `src/jsc/bindings/` and
`src/jsc/bindings/webcore/`. Every symbol was verified to have zero
callers across `src/` and `build/debug/codegen/`, and the full debug
build links cleanly.

No overlap with any open dead-code PR (#35437, #35559, #35775, #35880,
#36115, #36178, #36237, #36318, #36621, #36742).

### Whole files deleted

- `webcore/DOMJITCheckDOM.h` (98 LOC): only includer was
`JSEventDOMJIT.cpp`
- `webcore/JSEventDOMJIT.cpp` (43 LOC): defined
`checkSubClassSnippetForJSEvent`, whose sole reference in
`JSEvent.cpp:242` was behind `#if 0` (nullptr used instead)
- `webcore/DOMJITHelpers.cpp` (57 LOC): every function body was already
commented out; compiled to an empty namespace
- `webcore/JSDOMConvertSerializedScriptValue.h` (50 LOC): only includer
was the `JSDOMConvert.h` umbrella; `IDLSerializedScriptValue<>` was
never instantiated anywhere

### webcore/DOMJITHelpers.h

Removed the entire `WebCore::DOMJIT` namespace body (~184 LOC:
`branchIf*`, `toWrapper`, `tryLookUpWrapperCache`,
`operationToJSNode`/`operationToJSContainerNode` declarations, and ~60
LOC of commented-out helpers). All 7 remaining includers
(`generate-classes.ts` output, `JSBuffer.cpp`, `JSPerformance.cpp`,
`JSTextEncoder.cpp`, `JSFFIFunction.cpp`, `JSSQLStatement.cpp`,
`ZigGeneratedCode.cpp`) use only `JSC::DOMJIT::*` from JavaScriptCore
headers, never `WebCore::DOMJIT::*`. The transitive `#include`s are
kept.

### webcore/EventContext.{h,cpp}

Removed `handleLocalEvents`, `node()`, `relatedTarget()`,
`setRelatedTarget`, `isMouseOrFocusEventContext`, `isTouchEventContext`,
`isWindowContext`, `isUnreachableNode`, the `(Type, Node&, ...)`
constructor overload, the `Type` enum and `m_type` field,
`m_relatedTarget`, `m_contextNodeIsFormElement`, and all `TOUCH_EVENTS`
/ commented-out blocks. Only `currentTarget()` / `closedShadowDepth()` /
`target()` are reachable (via `EventPath::computePathUnclosedToTarget`).

### webcore/EventPath.{h,cpp}

Removed the empty `EventPath(Node&, Event&)` constructor, `contextAt`,
`eventTargetRespectingTargetRules`, the `buildPath` / `setRelatedTarget`
declarations (never defined), the `Touch` forward decl and
`TOUCH_EVENTS` block.

### webcore/EventListenerMap.{h,cpp}

Removed `removeFirstEventListenerCreatedFromMarkup`,
`copyEventListenersNotCreatedFromMarkupToTarget`, and their file-local
static helpers. WebKit markup-listener transfer helpers with zero
callers in Bun.

### ErrorCode.{h,cpp}

- `Bun::toJS(JSGlobalObject*, ErrorCode)`: declared, never defined,
never called
- `INVALID_FILE_URL_HOST(..., const ASCIILiteral)` overload: not
declared in the header, so the two call sites in `BunObject.cpp` bind to
the `const WTF::String&` overload
- `CRYPTO_JWK_UNSUPPORTED_CURVE(..., const WTF::String&)` overload: the
only call site in `KeyObject.cpp` passes `(ASCIILiteral, const char*)`,
matching the other overload
- `Message::ERR_INVALID_ARG_TYPE(..., const ZigString*, const
ZigString*, JSValue)` overload: zero callers

### DOMException.{h,cpp}

Removed `create(const Exception&)` (zero callers) and the static
`name(ExceptionCode)` / `message(ExceptionCode)` helpers (zero callers;
`description(ec).name` is used directly where needed).

### CookieMap.{h,cpp}

Removed `struct CookieStoreGetOptions` (zero references), `getAll()`
(not in the `JSCookieMap` prototype table; `toJSON()` enumerates
directly), and the private `CookieMap(Vector<Ref<Cookie>>&&)`
constructor (zero `adoptRef` sites use it).

### DOMFormData.{h,cpp}

Removed `clone()`; zero callers.

### Single-line declarations

- `Cookie.h`: `isValidCookieValue` (declared, never defined; the
trailing comment already said "this isn't needed")
- `ImportMetaObject.h`: `createRequireFunction` (declared, never
defined)
- `JSCommonJSModule.h`: `setSourceCode` (declared, never defined),
`clearSourceCode`, `idOrDot`
- `Sink.h`: `numberOfSinkIDs` constexpr
- `ProcessBindingTTYWrap.cpp`: duplicate forward declaration of
`Process_functionInternalGetWindowSize` (already declared via
`JSC_DECLARE_HOST_FUNCTION` in the header)

### Also scanned, nothing confidently dead

`src/http/`, `src/ast/`, `src/semver/`, `src/event_loop/`,
`src/bun_core/`, `src/threading/`, `src/runtime/bake/dev_server/`,
`src/js/thirdparty/`. All recently swept and clean.

### Intentionally not touched (possible followups)

-
`InspectorHTTPServerAgent::{requestWillBeSent,responseReceived,bodyChunkReceived,requestFinished,requestHandlerException}`
and
`InspectorBunFrontendDevServerAgent::{clientErrorReported,graphUpdate}`:
look like in-progress inspector scaffolding with matching Rust-side
extern declarations; left alone
- `webcore/streams/CrossRealmTransform.cpp` stubs: explicitly documented
as frozen-ABI placeholders for transferable streams
- `JSEventListener::wasCreatedFromMarkup()` and
`m_wasCreatedFromMarkup`: now the only readers are gone, but removing
the bitfield changes class layout; left for a separate pass
- `webcore/ResourceLoadTiming.h`: only includers are
`ResourceTiming.{h,cpp}` which #36621 modifies; avoided to prevent merge
conflicts

### Verification

- `rg -w <symbol> src/ build/debug/codegen/` returned only the
definition for every removed item
- `bun bd` builds and links
- Smoke tests: `test/js/bun/cookie/cookie-map.test.ts`,
`test/js/bun/globals.test.js`, `test/js/web/abort/abort.test.ts`,
`test/js/web/fetch/body.test.ts -t FormData` all pass
-
`test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.test.ts`
asserts the removed symbols do not reappear

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 4 · 29 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 3 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.test.ts
bun test v1.4.0 (1752533)

test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.test.ts:
28 |     ["src/jsc/bindings/webcore/JSDOMConvert.h", /JSDOMConvertSerializedScriptValue\.h/],
29 |     ["src/jsc/bindings/webcore/JSEvent.cpp", /checkSubClassSnippetForJSEvent/],
30 |     ["src/jsc/bindings/webcore/JSEvent.h", /checkSubClassSnippetForJSEvent/],
31 |   ];
32 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
33 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/DOMJITHelpers.h: namespace DOMJIT\b",
+   "src/jsc/bindings/webcore/DOMJITHelpers.h: branchIfNotWorldIsNormal|branchIfNotEvent|operationToJSNode",
+   "src/jsc/bindings/webcore/JSDOMConvert.h: JSDOMConvertSerializedScriptValue\.h",
+   "src/jsc/bindings/webcore/JSEvent.cpp: checkSubClassSnippetForJSEvent",
+   "src/jsc/bind
... (truncated)

release without fix: 3 FAILED
bun test v1.4.0-canary.1 (8fc0aeb)

test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.test.ts:
28 |     ["src/jsc/bindings/webcore/JSDOMConvert.h", /JSDOMConvertSerializedScriptValue\.h/],
29 |     ["src/jsc/bindings/webcore/JSEvent.cpp", /checkSubClassSnippetForJSEvent/],
30 |     ["src/jsc/bindings/webcore/JSEvent.h", /checkSubClassSnippetForJSEvent/],
31 |   ];
32 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
33 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/webcore/DOMJITHelpers.h: namespace DOMJIT\b",
+   "src/jsc/bindings/webcore/DOMJITHelpers.h: branchIfNotWorldIsNormal|branchIfNotEvent|operationToJSNode",
+   "src/jsc/bindings/webcore/JSDOMConvert.h: JSDOMConvertSerializedScriptValue\.h",
+   "src/jsc/bindings/webcore/JSEvent.cpp: checkSubClassSnippetForJSEvent",
+   "src/jsc/bindings/webcore/JSEvent.h: checkSubClassSnippetForJSEvent",
+ ]

- Expected  - 1
+ Received  + 7

      at <anonymous> (/workspace/bun/test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.test.ts
bun test v1.4.0 (1752533)

test/internal/source-lints/dead-symbols-domjit-eventpath-errorcode.test.ts:
(pass) webcore DOMJIT dead files and helpers do not reappear [15.85ms]
(pass) webcore EventPath/EventContext/EventListenerMap dead members do not reappear [19.37ms]
(pass) misc C++ bindings dead declarations do not reappear [28.64ms]

 3 pass
 0 fail
 3 expect() calls
Ran 3 tests across 1 file. [2.08s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 645ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/83] gen ErrorCode+*.h
[2/83] gen JSEvent.lut.h
Generating /workspace/bun/build/release/codegen/JSEvent.lut.h from /workspace/bun/src/jsc/bindings/webcore/JSEvent.cpp
[3/83] cxx obj/unified/UnifiedSource-src_jsc_bindings_node-0.cpp.o
[4/83] cxx obj/unified/UnifiedSource-src_jsc_bindings_v8-0.cpp.o
[5/83] cxx obj/unified/UnifiedSource-src_jsc_bindings_node_http-0.cpp.o
[6/83] cxx obj/unified/UnifiedSource-src_jsc_bindings-5.cpp.o
[7/83] gen cpp.rs (cppbind)
[8/83] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 239 extern-C blocks audited
[8/83] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

�[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
�[1m�[92m   Compiling�[0m bun_errno v0.0.0 (/workspace/bun/src/errno)
�[1m�[92m   Compiling�[0m bun_ptr v0.0.0 (/workspace/bun/src/ptr)
�[1m�[92m   Compiling�[0m bun
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/jsc/bindings/Cookie.h                          |   1 -
 src/jsc/bindings/CookieMap.cpp                     |  18 --
 src/jsc/bindings/CookieMap.h                       |   7 -
 src/jsc/bindings/DOMException.cpp                  |   8 -
 src/jsc/bindings/DOMException.h                    |   6 -
 src/jsc/bindings/DOMFormData.cpp                   |   8 -
 src/jsc/bindings/DOMFormData.h                     |   1 -
 src/jsc/bindings/ErrorCode.cpp                     |  29 ----
 src/jsc/bindings/ErrorCode.h                       |   2 -
 src/jsc/bindings/IDLTypes.h                        |   2 -
 src/jsc/bindings/ImportMetaObject.h                |   2 -
 src/jsc/bindings/JSCommonJSModule.h                |   5 -
 src/jsc/bindings/ProcessBindingTTYWrap.cpp         |   2 -
 src/jsc/bindings/Sink.h                            |   2 -
 src/jsc/bindings/webcore/DOMJITCheckDOM.h          |  98 +----------
 src/jsc/bindings/webcore/DOMJITHelpers.cpp         |  57 +------
 src/jsc/bindings/webcore/DOMJITHelpers.h           | 185 ---------------------
 src/jsc/bindings/webcore/EventContext.cpp          |  34 ----
 src/jsc/bindings/webcore/EventContext.h            | 116 +------------
 src/jsc/bindings/webcore/EventListenerMap.cpp      |  45 -----
 src/jsc/bindings/webcore/EventListenerMap.h        |   5 -
 src/jsc/bindings/webcore/EventPath.cpp             |  18 +-
 src/jsc/bindings/webcore/EventPath.h               |  37 -----
 src/jsc/bindings/webcore/JSDOMConvert.h            |   1 -
 .../webcore/JSDOMConvertSerializedScriptValue.h    |  50 +-----
 src/jsc/bindings/webcore/JSEvent.cpp               |  10 +-
 src/jsc/bindings/webcore/JSEvent.h                 |   4 -
 src/jsc/bindings/webcore/JSEventDOMJIT.cpp         |  43 +----
 ...dead-symbols-domjit-eventpath-errorcode.test.ts |  90 ++++++++++
 29 files changed, 101 insertions(+), 785 deletions(-)
```

</details>

**gate history** · 5 passed · 2 rejected · iteration 4

<details><summary>evidence per changed file</summary>

```
file                                        reads  edits  tests
src/jsc/bindings/Cookie.h                       2      1      0
src/jsc/bindings/CookieMap.cpp                  2      1      0
src/jsc/bindings/CookieMap.h                    2      3      0
src/jsc/bindings/DOMException.cpp               2      3      0
src/jsc/bindings/DOMException.h                 2      3      0
src/jsc/bindings/DOMFormData.cpp                1      1      0
src/jsc/bindings/DOMFormData.h                  1      1      0
src/jsc/bindings/ErrorCode.cpp                  1      1      0
src/jsc/bindings/ErrorCode.h                    1      1      0
src/jsc/bindings/IDLTypes.h                     1      1      0
src/jsc/bindings/ImportMetaObject.h             2      1      0
src/jsc/bindings/JSCommonJSModule.h             1      2      0
src/jsc/bindings/ProcessBindingTTYWrap.cpp      2      1      0
src/jsc/bindings/Sink.h                         2      1      0
src/jsc/bindings/webcore/DOMJITCheckDOM.h       0      1      0
src/jsc/bindings/webcore/DOMJITHelpers.cpp      1      1      0
(+ 13 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
Jarred-Sumner added a commit that referenced this pull request Aug 2, 2026
…36742)

Part of the recurring dead-code sweep. 311 deletions / 97 insertions
across 34 source files. Every removed item was verified to have zero
references across `src/` and `build/debug/codegen/`, then confirmed by a
clean `bun bd` build and `bun run rust:check-all` (10/10 targets).

## C++ (`src/jsc/bindings/`)

### napi
- `Napi::generateSourceCode()` (napi.cpp, napi.h): 26 LOC, zero callers.
`rg generateSourceCode src/ build/debug/codegen/` finds only the
definition and declaration. The `namespace JSC { JSGlobalObject;
JSSourceCode; }` forward-decl block that sat above it is dropped with
it.
-
`NapiWeakValue::isSet`/`isPrimitive`/`isCell`/`isString`/`cell()`/`primitive()`/`string()`
(napi.h): accessor set never called; only `get()` is used. `NapiRef.cpp`
explicitly avoids `isSet()`; the two comment lines there that referenced
it are dropped too.
- `NapiClass::destroy` (napi.h): unreachable with `needsDestruction =
DoesNotNeedDestruction` on the same class.

### NodeVM
- `NodeVMGlobalObject::clearContextifiedObject()`: zero callers.
- `NodeVMModuleRequest::addImportAttribute` + `specifier(WTF::String)`
setter: zero callers (only the getter is used).
- `NodeVMSourceTextModule::hasModuleRecord` /
`NodeVMSyntheticModule::hasModuleRecord`: zero callers
(`moduleRecordIfExists()` covers the same check).
- `NodeVMScript::cachedBytecode()`: zero callers; the field is accessed
directly.

### JSBufferList / JSStringDecoder
- `JSBufferListConstructor::initializeProperties`: empty body, never
called.
- `JSBufferList::destroy(JSCell*)`: unreachable on a `JSNonFinalObject`
without `NeedsDestruction`.
- `JSStringDecoderConstructor::initializeProperties`: never called;
`finishCreation` (cpp:552) already sets name/length/prototype.

### BunClientData
- `JSVMClientData::outputConstraintSpaces()` /
`forEachOutputConstraintSpace()` / `m_outputConstraintSpaces`:
duplicates of the `JSHeapData` members at the top of the file. Both real
callers (`BunGCOutputConstraint.cpp:126` and `BunClientData.h:227`)
dispatch on `heapData`, never on `JSVMClientData`.

### EventLoopTask
- `m_isCleanupTask` field, `isCleanupTask()` getter, `CleanupTaskTag`
constructor: the bool is written in every constructor but never read.
`DeleteCallbackDataTask` now uses the primary templated constructor
(identical behaviour).

### initialValues() statics
- `JSNextTickQueue::initialValues()`,
`PendingVirtualModuleResult::initialValues()` (ModuleLoader.h),
`MockWithImplementationCleanupData::initialValues()` (JSMockFunction.h):
never invoked; each `finishCreation` sets every internal field directly.
`BunStreamSource::initialValues()` is kept (live caller at
BunStreamSource.cpp:57).

### Misc
- `JSEnvironmentVariableMap.cpp`: `jsSetterEnvironmentVariable`
(registered with `nullptr`; only referenced in a comment, which is
updated).
- `JSBuffer.cpp`: commented-out
`jsBufferPrototypeToStringWithoutTypeChecks` DOMJIT block (23 LOC,
unchanged since Jan 2025).
- `blob.h`: unused `BlobRef` type alias (`BlobRefPtr` is the one used).
- `Bindgen/IDLTypes.h`: unused `IsIDLStrongAny` trait.

## Rust

- `src/zlib/error.rs` (whole file, 31 LOC): defines `Error`/`Result`
that nothing imports; the crate uses `ZlibError` from `lib.rs` instead.
`rg 'bun_zlib::Error|bun_zlib::Result|zlib::error::'` across `src/`
returns nothing. The `thiserror` dep it required is dropped from
`src/zlib/Cargo.toml`.
- `src/zlib/lib.rs`: dropped `Byte`/`gzFile`/`struct_gzFile_s`/`voidpf`
from the `bun_zlib_sys::shared` re-export (zero Rust-side references),
and the now no-op `#[allow(...)]` above it.
- `src/io/windows_event_loop.rs`: `FilePoll::ref_`/`activate`/`can_ref`
(30 LOC). No caller targets `FilePoll` for any of these; all
`.ref_()`/`.activate()` call sites in the tree dispatch on `KeepAlive`,
`Source`, `Pipe`, `Timer`, or `Progress`. The
`declare_scope!(FilePoll)`/`declare_scope!(KeepAlive)` statics that only
those methods logged through are dropped, and the stale `ref()`
reference in the `disable_keeping_process_alive` doc is reworded.
Verified on all 10 `rust:check-all` targets including both Windows
triples.
- `src/io/posix_event_loop.rs`: the posix `FilePoll::ref_` sibling (same
justification), and the `declare_scope!(KeepAlive)` static with zero
`scoped_log!` callers.
- `src/install/lockfile/bun.lock.rs`: commented-out `Stringifier::save`
stub.
- `src/install/lockfile/Buffers.rs`: four empty
`#[cfg(debug_assertions)] { /* commented print */ }` blocks on the save
side, and the three orphaned `let _pos = stream.pos` bindings on the
load side that fed them.

## TypeScript

- `src/js/node/net.ts`: `kpendingRead` private `Symbol()` (defined,
written once as `this[kpendingRead] = undefined`, never read).

`kServerSocket` was initially removed too but **restored** in
a93d2fa: the write `clientHandle[kServerSocket] = handle` is a GC
retention edge from accepted socket handle to native Listener, and
removing it crashed `sql-close-pending-connection.test.ts` on 6 CI lanes
(build #87459) via `Listener::finalize` firing JS `on_close` during a GC
sweep. A two-line comment now documents why the symbol exists; the
underlying Listener-finalizer-calls-JS-during-sweep issue is tracked
separately.

## Verification

```
$ bun bd
[build] done
$ bun run rust:check-all
10 ok, 0 failed, 0 skipped (of 10)
$ bun bd test test/internal/source-lints/dead-symbols-napi-nodevm-libuv.test.ts
3 pass, 0 fail
```

Smoke tests on `test/js/node/vm`, `test/js/node/string_decoder`,
`test/js/node/net`, `test/js/sql/sql-close-pending-connection.test.ts`,
and `test/js/node/process -t env` show identical pass/fail counts with
and without this diff.

## Notes

- The vendored libuv headers (`src/jsc/bindings/libuv/uv/*`) are not
touched (reverted in 4dd5a99 per review).
- `napi.cpp` also appears in #35775, which removes different symbols
(`napi_set_ref`, `napi_internal_get_version`); no line overlap.
- `src/zlib/Cargo.toml` also appears in #35880, which removes different
deps (bstr/scopeguard/etc.); no deletion overlap.
- `src/io/posix_event_loop.rs` also appears in #35880 at lines 1562+;
this PR touches line 562, no overlap.
- Areas scanned with nothing confidently dead (left alone): `src/http/`
(HTTP client), `src/valkey/`, `src/patch/`, `src/semver/`,
`src/semver_jsc/`.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 5 · 34 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 3 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-napi-nodevm-io-zlib.test.ts
bun test v1.4.0 (0a3dcec)

test/internal/source-lints/dead-symbols-napi-nodevm-io-zlib.test.ts:
47 |     ["src/jsc/bindings/JSNextTickQueue.h", /static std::array<JSValue, numberOfInternalFields> initialValues\(\)/],
48 |     ["src/jsc/bindings/ModuleLoader.h", /static std::array<JSValue, numberOfInternalFields> initialValues\(\)/],
49 |     ["src/jsc/bindings/JSMockFunction.h", /static std::array<JSValue, numberOfInternalFields> initialValues\(\)/],
50 |   ];
51 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
52 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/napi.cpp: JSC::SourceCode generateSourceCode\(WTF::String keyString",
+   "src/jsc/bindings/napi.h: JSC::SourceCode generateSourceCode\(",
+   "src/jsc/bindings/napi.h: bool isSet\(\) const \{ return m_tag != WeakTypeTag::NotSet; \}",
+   "src/jsc/bi
... (truncated)

release without fix: 3 FAILED
bun test v1.4.0-canary.1 (4dd5a99)

test/internal/source-lints/dead-symbols-napi-nodevm-io-zlib.test.ts:
47 |     ["src/jsc/bindings/JSNextTickQueue.h", /static std::array<JSValue, numberOfInternalFields> initialValues\(\)/],
48 |     ["src/jsc/bindings/ModuleLoader.h", /static std::array<JSValue, numberOfInternalFields> initialValues\(\)/],
49 |     ["src/jsc/bindings/JSMockFunction.h", /static std::array<JSValue, numberOfInternalFields> initialValues\(\)/],
50 |   ];
51 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
52 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/napi.cpp: JSC::SourceCode generateSourceCode\(WTF::String keyString",
+   "src/jsc/bindings/napi.h: JSC::SourceCode generateSourceCode\(",
+   "src/jsc/bindings/napi.h: bool isSet\(\) const \{ return m_tag != WeakTypeTag::NotSet; \}",
+   "src/jsc/bindings/napi.h: JSCell\* cell\(\) const\s*\{",
+   "src/jsc/bindings/napi.h: JSValue primitive\(\) const\s*\{",
+   "src/jsc/bindings/napi.h: JSString\* string\(\) const\s*\{",
+   "src/jsc/bin
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-napi-nodevm-io-zlib.test.ts
bun test v1.4.0 (0a3dcec)

test/internal/source-lints/dead-symbols-napi-nodevm-io-zlib.test.ts:
(pass) napi / NodeVM / JSBufferList / JSStringDecoder dead methods do not reappear [50.20ms]
(pass) BunClientData / EventLoopTask / JSEnvironmentVariableMap / blob / Bindgen dead members do not reappear [18.61ms]
(pass) zlib / io / install / net.ts dead items do not reappear [23.73ms]

 3 pass
 0 fail
 6 expect() calls
Ran 3 tests across 1 file. [2.09s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 688ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/122] gen JSBuffer.lut.h
Generating /workspace/bun/build/release/codegen/JSBuffer.lut.h from /workspace/bun/src/jsc/bindings/JSBuffer.cpp
[2/122] gen cpp.rs (cppbind)
[3/122] gen JS modules (bundle-modules)
Preprocess modules (8780ms)
Bundle modules (62ms)
Postprocesss modules (25ms)
Bundle Functions (633ms)
Generate Code (21ms)

[9.54s] Bundled "src/js" for production
  2561 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[3/121] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

�[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
�[1m�[92m   Compiling�[0m bun_errno v0.0.0 (/workspace/bun/src/errno)
�[1m�[92m   Compiling�[0m bun_ptr v0.0.0 (/workspace/bun/src/ptr)
�[1m�[92m   Compiling�[0m bun_boringssl_sys v0.0.0 (/workspace/bun/src/boringssl_sys)
�[1m�[92m   Compiling�[0m bun_safety v0.0.0 (/workspace/bun/src/safety)
�[1m�[92
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
Cargo.lock                                         |  1 -
 src/install/lockfile/Buffers.rs                    | 24 ------
 src/install/lockfile/bun.lock.rs                   |  4 -
 src/io/posix_event_loop.rs                         | 11 ---
 src/io/windows_event_loop.rs                       | 35 +-------
 src/js/node/net.ts                                 |  4 +-
 src/jsc/bindings/Bindgen/IDLTypes.h                |  3 -
 src/jsc/bindings/BunClientData.h                   |  9 ---
 src/jsc/bindings/DeleteCallbackDataTask.h          |  2 +-
 src/jsc/bindings/EventLoopTask.h                   | 13 ---
 src/jsc/bindings/JSBuffer.cpp                      | 24 ------
 src/jsc/bindings/JSBufferList.cpp                  |  4 -
 src/jsc/bindings/JSBufferList.h                    |  3 -
 src/jsc/bindings/JSEnvironmentVariableMap.cpp      | 25 +-----
 src/jsc/bindings/JSMockFunction.h                  | 10 ---
 src/jsc/bindings/JSNextTickQueue.h                 |  9 ---
 src/jsc/bindings/JSStringDecoder.cpp               |  9 ---
 src/jsc/bindings/JSStringDecoder.h                 |  2 -
 src/jsc/bindings/ModuleLoader.h                    |  9 ---
 src/jsc/bindings/NapiRef.cpp                       |  2 -
 src/jsc/bindings/NodeVM.cpp                        |  5 --
 src/jsc/bindings/NodeVM.h                          |  1 -
 src/jsc/bindings/NodeVMModule.cpp                  |  5 --
 src/jsc/bindings/NodeVMModule.h                    |  2 -
 src/jsc/bindings/NodeVMScript.h                    |  1 -
 src/jsc/bindings/NodeVMSourceTextModule.h          |  1 -
 src/jsc/bindings/NodeVMSyntheticModule.h           |  1 -
 src/jsc/bindings/blob.h                            |  1 -
 src/jsc/bindings/napi.cpp                          | 26 ------
 src/jsc/bindings/napi.h                            | 34 --------
 src/zlib/Cargo.toml                                |  1 -
 src/zlib/error.rs                                  | 31 --------
 src/zlib/lib.rs                      
... (truncated)
```

</details>

**gate history** · 8 passed · 0 rejected · iteration 5

<details><summary>evidence per changed file</summary>

```
file                                           reads  edits  tests
Cargo.lock                                         0      0      0
src/install/lockfile/Buffers.rs                    4      2      0
src/install/lockfile/bun.lock.rs                   1      1      0
src/io/posix_event_loop.rs                         2      2      0
src/io/windows_event_loop.rs                       2      2      0
src/js/node/net.ts                                 6      4      0
src/jsc/bindings/Bindgen/IDLTypes.h                1      1      0
src/jsc/bindings/BunClientData.h                   1      2      0
src/jsc/bindings/DeleteCallbackDataTask.h          1      1      0
src/jsc/bindings/EventLoopTask.h                   2      1      0
src/jsc/bindings/JSBuffer.cpp                      1      1      0
src/jsc/bindings/JSBufferList.cpp                  1      1      0
src/jsc/bindings/JSBufferList.h                    1      1      0
src/jsc/bindings/JSEnvironmentVariableMap.cpp      3      3      0
src/jsc/bindings/JSMockFunction.h                  1      1      0
src/jsc/bindings/JSNextTickQueue.h                 1      1      0
(+ 18 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
Jarred-Sumner added a commit that referenced this pull request Aug 2, 2026
…_types, sql/postgres (#36318)

Net -1029 lines (1181 deletions, 152 insertions including the
source-lint test).

No file overlaps with the other open dead-code PRs (#34965, #34759,
#35437, #35559, #35775, #35880, #36115, #36178, #36237).

## C++ bindings (~620 lines)

- **`DecodeEscapeSequences.h`** (whole file, 187 lines): only `#include`
was `TextEncoding.cpp`, whose only consumer `decodeURLEscapeSequences()`
is itself dead.
- **`TextEncoding.{cpp,h}`**: `domName`, `usesVisualOrdering`,
`isJapanese`, `isNonByteBasedEncoding`, `isUTF7Encoding`,
`closestByteBasedEquivalent`, `encodingForFormSubmissionOrURLParsing`,
`ASCIIEncoding`, `Latin1Encoding`, `UTF16BigEndianEncoding`,
`UTF16LittleEndianEncoding`, `WindowsLatin1Encoding`,
`decodeURLEscapeSequences`, `UTF7Encoding`, `isByteBasedEncoding`. These
formed a closed call graph with no outside caller; only `UTF8Encoding()`
remains.
- **`TextEncodingRegistry.{cpp,h}`**: `isJapaneseEncoding` +
`japaneseEncodings()` static set + its 14 `addEncodingName` calls,
`noExtendedTextEncodingNameUsed`,
`defaultTextEncodingNameForSystemLanguage`, `webDefaultCFStringEncoding`
decl, and the `CoreFoundation.h` include. All were only reached from the
removed `TextEncoding` methods.
- **`JSDOMExceptionHandling.{cpp,h}`**:
`retrieveErrorMessageWithoutName`, `reportCurrentException`,
`throwNotSupportedError`, `throwInvalidStateError`,
`throwSecurityError`, `throwAttributeTypeError`,
`makeUnsupportedIndexedSetterErrorMessage`, `throwDOMSyntaxError`,
`reportExceptionIfJSDOMWindow`, and the now-orphaned static
`throwTypeError` helper. `rg` across `src/` and `build/debug/codegen/`
shows zero callers outside decl/defn.
- **`DOMURL.{cpp,h}`**:
`DOMURL::createObjectURL`/`revokeObjectURL`/`createPublicURL` C++ stubs,
the `URLRegistrable`/`Blob` placeholder classes, and the commented-out
includes. Real implementations are
`Bun__createObjectURL`/`Bun__revokeObjectURL` in Rust; the C++ stubs
were only referenced from commented-out code in `JSDOMURL.cpp`.
- **`webcore/JSDOMURL.cpp`**:
`jsDOMURLConstructorFunction_createObjectURL` / `_revokeObjectURL` /
`_createObjectURL1Body` / `_revokeObjectURLBody` /
`_createObjectURLOverloadDispatcher` and their forward decls. The hash
table at `:140-141` routes to
`Bun__createObjectURL`/`Bun__revokeObjectURL` instead.
- **`DOMWrapperWorld-class.h` / `DOMWrapperWorld.cpp`**:
`clearWrappers`, `didCreateWindowProxy`, `didDestroyWindowProxy`,
`setShadowRootIsAlwaysOpen`/`shadowRootIsAlwaysOpen`,
`disableLegacyOverrideBuiltInsBehavior`/`shouldDisableLegacyOverrideBuiltInsBehavior`,
`m_jsWindowProxies`, `m_shadowRootIsAlwaysOpen`,
`m_shouldDisableLegacyOverrideBuiltInsBehavior`, `class WindowProxy` fwd
decl. `WindowProxy` is never defined.
- **`ActiveDOMCallback.{cpp,h}`**:
`activeDOMObjectsAreSuspended`/`activeDOMObjectAreStopped`. Only
external references are in commented-out code in
`JSDOMPromiseDeferred.cpp` and `ActiveDOMObject.cpp`.

## src/js internals (~370 lines)

- **`internal/assert/utils.ts`**: 230 lines of commented-out acorn-based
source-parsing scaffolding
(`findColumn`/`getCode`/`parseCode`/`escapeSequencesRegExp`/`meta`/`escapeFn`)
plus the `getErrMessage()` body, which always returned `undefined`.
Inlined `undefined` at its one call site. Blame: 2025-01-10.
- **`internal/util/inspect.js`**: commented-out
`stylizeWithColor`/`stylizeWithHTML`/`entities`/`escapeHTML` block
annotated "unused without stylizeWithHTML". Blame: 2023-09-28.
- **`node/_http_server.ts`**: commented-out `fetch(req, _server)`
handler inside `Bun.serve({...})`, superseded by native dispatch.
Commented out 2025-04-21.
- **`internal/cluster/primary.ts`**: commented-out
`inspectPort`/`isUsingInspector` block. Blame: 2024-08-18.
- **`internal/streams/utils.ts`**: `isReadableEnded` (exported from an
internal module, zero consumers across `src/` and codegen).
- **`internal/sql/shared.ts`**:
`isOptionsOfAdapter`/`assertIsOptionsOfAdapter` (zero consumers).
- **`internal/primordials.js`**: `SafePromiseAll` +
`arrayToSafePromiseIterable` + `PromiseAll` + `ArrayPrototypeMap`. Only
`SafePromiseAllReturnVoid`/`ReturnArrayLike` are consumed, via
`safePromiseAllCollect` which does not use these.
- **`internal/validators.ts`**: `validateInternalField` + its
`ObjectPrototypeHasOwnProperty` capture (zero consumers).

## Rust (~190 lines)

- **`http_types/h2.rs`**: `FullSettingsPayload` (struct +
`Pod`/`Zeroable`/`Default`/`BYTE_SIZE`, ~50 lines). `pub(crate)` with
zero references; `runtime/api/bun/h2_frame_parser.rs` has its own local
copy and does not import this one. Also `StreamPriority::from` + its
`Pod`/`Zeroable` impls, `UInt31WithReserved::init`, and
`SettingsType::SETTINGS_ENABLE_CONNECT_PROTOCOL` (only used by the
removed `FullSettingsPayload::default`).
- **`http_types/mime_type_list_enum.rs`**: `MimeTypeList::{as_str,
len}`. Callers use `<&'static str>::from(entry)` and slice `.len()` on
`Table::ALL` instead.
- **`sql/postgres/protocol/*`**: `impl Default` for
`StartupMessage`/`SASLInitialResponse`/`PasswordMessage`/`FieldDescription`/`ReadyForQuery`.
Each struct is constructed with all fields explicit at its call site(s)
in `PostgresSQLConnection.rs`; `::default()` is never called and no `T:
Default` bound needs them. `TransactionStatusIndicator::I` goes with
them (only used by the removed `ReadyForQuery::default`).
- **`runtime/valkey_jsc/index.rs`** (whole file) + `mod index` decl +
`ValkeyCommand` re-export alias in `mod.rs`. Every re-export in
`index.rs` was already re-exported by `mod.rs` itself; zero external
imports resolve through `valkey_jsc::index::` or `::ValkeyCommand`.
- **`bun_core/string/MutableString.rs`**: `index_of`, `eql`.
- **`s3_signing/credentials.rs`**: a stale "DELETED" reminder comment.

## Verification

For each symbol: `rg` across `src/` and `build/debug/codegen/` showed
zero references outside its own definition (or only references from
other removed symbols). None are `#[no_mangle]`/`extern
"C"`/`#[export_name]`, none are named by string in `.classes.ts` or
`src/codegen/*.ts`, none are trait impls required by a live trait bound.

`bun bd` and `bun run rust:check-all` (all 10 targets including windows
x64/aarch64, macOS, musl, freebsd, android) pass. Smoke tests pass for
`text-decoder.test.js`, `url.test.ts`, node assert,
`util-inspect.test.js`, `node-http.test.ts` (the one proxy failure there
also reproduces on the system bun), node stream, and cluster.

`test/internal/source-lints/dead-symbols-text-encoding-domurl.test.ts`
guards against reintroduction.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 7 · 31 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 3 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-text-encoding-domurl.test.ts
bun test v1.4.0 (fec8e5e)

test/internal/source-lints/dead-symbols-text-encoding-domurl.test.ts:
22 |     ["src/jsc/bindings/webcore/JSDOMURL.cpp", /jsDOMURLConstructorFunction_createObjectURL\b/],
23 |     ["src/jsc/bindings/DOMWrapperWorld-class.h", /clearWrappers|didCreateWindowProxy|m_jsWindowProxies/],
24 |     ["src/jsc/bindings/ActiveDOMCallback.cpp", /ActiveDOMCallback::activeDOMObjectsAreSuspended/],
25 |   ];
26 |   const found = checks.filter(([f, re]) => re.test(src(f))).map(([f, re]) => `${f}: ${re.source}`);
27 |   expect(found).toEqual([]);
                     ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/TextEncoding.cpp: decodeURLEscapeSequences|UTF7Encoding|domName",
+   "src/jsc/bindings/TextEncoding.cpp: encodingForFormSubmissionOrURLParsing|WindowsLatin1Encoding",
+   "src/jsc/bindings/TextEncodingRegistry.cpp: isJapaneseEncoding|defaultTextEncodingNameForSystemLanguage",
+   "src/jsc/bindings/JSDOMExceptionHandlin
... (truncated)

release without fix: 3 FAILED
bun test v1.4.0-canary.1 (3a6d57a)

test/internal/source-lints/dead-symbols-text-encoding-domurl.test.ts:
22 |     ["src/jsc/bindings/webcore/JSDOMURL.cpp", /jsDOMURLConstructorFunction_createObjectURL\b/],
23 |     ["src/jsc/bindings/DOMWrapperWorld-class.h", /clearWrappers|didCreateWindowProxy|m_jsWindowProxies/],
24 |     ["src/jsc/bindings/ActiveDOMCallback.cpp", /ActiveDOMCallback::activeDOMObjectsAreSuspended/],
25 |   ];
26 |   const found = checks.filter(([f, re]) => re.test(src(f))).map(([f, re]) => `${f}: ${re.source}`);
27 |   expect(found).toEqual([]);
                     ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/jsc/bindings/TextEncoding.cpp: decodeURLEscapeSequences|UTF7Encoding|domName",
+   "src/jsc/bindings/TextEncoding.cpp: encodingForFormSubmissionOrURLParsing|WindowsLatin1Encoding",
+   "src/jsc/bindings/TextEncodingRegistry.cpp: isJapaneseEncoding|defaultTextEncodingNameForSystemLanguage",
+   "src/jsc/bindings/JSDOMExceptionHandling.cpp: throwNotSupportedError|throwSecurityError|throwDOMSyntaxError",
+   "src/jsc/bindings/JSDOMExceptionHandling.cpp: retrieveErrorMessageWithoutName|reportCurrentException",
+   "src/jsc/bi
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-text-encoding-domurl.test.ts
bun test v1.4.0 (fec8e5e)

test/internal/source-lints/dead-symbols-text-encoding-domurl.test.ts:
(pass) dead TextEncoding/DOMURL/JSDOMExceptionHandling C++ does not reappear [26.22ms]
(pass) dead src/js internal helpers and commented-out blocks do not reappear [16.15ms]
(pass) dead http_types/h2 and postgres Default impls do not reappear [9.38ms]

 3 pass
 0 fail
 3 expect() calls
Ran 3 tests across 1 file. [2.06s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped)
  target       linux-x64-gnu
  build type   Release
  build dir    ./build/release
  revision     fec8e5e
  features     baseline

22 deps, 108 codegen, 1171 objects in 725ms

ninja: Entering directory `/workspace/bun/build/release'
[1/138] gen ErrorCode+*.h
[2/138] gen bake.{client,server,error}.js
-> bake.client.js, bake.server.js, bake.error.js
[3/138] gen JSEvent.lut.h
Generating /workspace/bun/build/release/codegen/JSEvent.lut.h from /workspace/bun/src/jsc/bindings/webcore/JSEvent.cpp
[4/138] gen JSBuffer.lut.h
Generating /workspace/bun/build/release/codegen/JSBuffer.lut.h from /workspace/bun/src/jsc/bindings/JSBuffer.cpp
[5/138] gen cpp.rs (cppbind)
[6/138] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 6 sinks, 72 exported symbols
Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt
[7/138] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 239 extern-C blocks audited
[8/138] gen JS modules (bundle-modules)
Preprocess modules (8754ms)
Bundle modules (3
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/http_types/h2.rs                               |  63 ------
 src/js/internal/assert/utils.ts                    | 240 +--------------------
 src/js/internal/cluster/primary.ts                 |   7 -
 src/js/internal/primordials.js                     |  13 --
 src/js/internal/sql/shared.ts                      |  18 --
 src/js/internal/streams/utils.ts                   |  11 -
 src/js/internal/util/inspect.js                    |  26 ---
 src/js/internal/validators.ts                      |  11 +-
 src/js/node/_http_server.ts                        |  53 -----
 src/jsc/bindings/ActiveDOMCallback.cpp             |  12 --
 src/jsc/bindings/ActiveDOMCallback.h               |   3 -
 src/jsc/bindings/DOMURL.cpp                        |  51 -----
 src/jsc/bindings/DOMURL.h                          |   8 -
 src/jsc/bindings/DOMWrapperWorld-class.h           |  18 --
 src/jsc/bindings/DOMWrapperWorld.cpp               |   5 -
 src/jsc/bindings/DecodeEscapeSequences.h           | 187 ----------------
 src/jsc/bindings/JSDOMExceptionHandling.cpp        |  67 ------
 src/jsc/bindings/JSDOMExceptionHandling.h          |  10 -
 src/jsc/bindings/TextEncoding.cpp                  | 108 ----------
 src/jsc/bindings/TextEncoding.h                    |  22 --
 src/jsc/bindings/TextEncodingRegistry.cpp          |  61 ------
 src/jsc/bindings/TextEncodingRegistry.h            |  12 --
 src/jsc/bindings/webcore/JSDOMURL.cpp              |  65 ------
 src/runtime/valkey_jsc/index.rs                    |  20 --
 src/runtime/valkey_jsc/mod.rs                      |  11 -
 src/s3_signing/credentials.rs                      |   3 -
 src/sql/postgres/protocol/FieldDescription.rs      |  10 -
 src/sql/postgres/protocol/PasswordMessage.rs       |  11 -
 src/sql/postgres/protocol/SASLInitialResponse.rs   |  12 --
 src/sql/postgres/protocol/StartupMessage.rs        |  10 -
 .../dead-symbols-text-encoding-domurl.test.ts      |  54 +++++
 31 files changed, 57 insertions(+), 1145 deletions(-)
```

</details>

**gate history** · 3 passed · 2 rejected · iteration 7

<details><summary>evidence per changed file</summary>

```
file                                      reads  edits  tests
src/http_types/h2.rs                          3      7      0
src/js/internal/assert/utils.ts               1      1      0
src/js/internal/cluster/primary.ts            1      1      0
src/js/internal/primordials.js                1      2      0
src/js/internal/sql/shared.ts                 1      2      0
src/js/internal/streams/utils.ts              1      2      0
src/js/internal/util/inspect.js               1      1      0
src/js/internal/validators.ts                 2      4      0
src/js/node/_http_server.ts                   1      1      0
src/jsc/bindings/ActiveDOMCallback.cpp        1      1      0
src/jsc/bindings/ActiveDOMCallback.h          1      1      0
src/jsc/bindings/DOMURL.cpp                   4      6      0
src/jsc/bindings/DOMURL.h                     2      3      0
src/jsc/bindings/DOMWrapperWorld-class.h      1      3      0
src/jsc/bindings/DOMWrapperWorld.cpp          1      1      0
src/jsc/bindings/DecodeEscapeSequences.h      1      3      0
(+ 15 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
Comment thread src/jsc/bindings/ErrorStackTrace.cpp Outdated
Comment thread test/internal/source-lints/dead-symbols-cpp-webcore.test.ts Outdated
…p guard test

Bun__errorInstance__finalize is referenced by JSC::ErrorInstance::finalizeUnconditionally
in vendor/WebKit/Source/JavaScriptCore/runtime/ErrorInstance.cpp via a weak
declaration and forced into the link by -Wl,-u in WebKitCompilerFlags.cmake,
so removing it breaks the macOS release link. Restored with a comment pointing
at the caller.

Also drop test/internal/source-lints/dead-symbols-cpp-webcore.test.ts per
REVIEW.md line 56 ("Do not add tests to check dead code stays dead", added
in 907f57b). The build passing without the removed symbols is the proof.
@robobun
robobun force-pushed the claude/farm/cf1ec6e4/dead-code-cpp-webcore-js-rust branch from 62d5da0 to 3d5c5f7 Compare August 2, 2026 08:12

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the guard test and long comment from earlier feedback are both addressed; remaining diff is pure dead-code removal.

What was reviewed:

  • Verified every removed extern "C" symbol (napi_set_ref, napi_internal_get_version, rescle__setIcon, Bun__NodeCrypto__createCryptoError, Process_defaultSetter) has zero references across src/, vendor/, and scripts/ — the same check that caught Bun__errorInstance__finalize.
  • Confirmed the 9 deleted webcore headers are not #include'd anywhere and the removed BunPlugin Node/Browser host-function variants are never registered.
  • http2.ts removed consts and kGetNativeReadableProto have no remaining readers; the child_process/url/serialized_failure/subproc hunks delete only commented-out code.
Extended reasoning...

Overview

Net -1113 lines across 24 files: 9 never-included webcore headers deleted outright; static/file-local helpers in JSMIMEType.cpp and FormatStackTraceForJS.cpp; unregistered JSC_DEFINE_HOST_FUNCTION variants in BunPlugin.cpp; unreferenced extern "C" symbols in napi.cpp, CryptoUtil.cpp, BunProcess.cpp, rescle-binding.cpp; commented-out blocks in four TS/Rust files; unused top-level consts in http2.ts; and one exported Symbol from internal/shared.ts. The only additive change is a one-line provenance comment on the restored Bun__errorInstance__finalize.

Security risks

None. This is pure code deletion with no logic, control-flow, or data-handling changes.

Level of scrutiny

Moderate. The line count is large but each hunk is independently verifiable by grep. The genuinely risky category is extern "C" removals, which can be referenced from Rust FFI, vendored WebKit, or linker -Wl,-u flags without appearing in src/. That risk was already exercised once (Bun__errorInstance__finalize, caught by darwin link and restored). I re-verified the remaining five extern "C" removals against vendor/ and scripts/ in addition to src/ — all clean. Static functions and deleted headers are proven dead by the build compiling. Commented-out code and unused module-level consts carry no runtime risk.

Other factors

All prior review threads are resolved: the source-lint guard test was dropped per REVIEW.md's "do not add tests to check dead code stays dead" rule (my earlier comment), and the multi-line Bun__errorInstance__finalize comment was shortened per the comment-cop bot. The change follows the same shape as recently-merged siblings #36742 and #36756. The PR description enumerates the verification methodology per symbol, and the debug build passes.

Jarred-Sumner pushed a commit that referenced this pull request Aug 3, 2026
… and resolver/fs (#36803)

Net: +47 / -1160.

## Removed

- **`src/runtime/node/nodejs_error_code.rs`** (1113 lines): a
340-variant `enum Code` mirroring the Node.js `ERR_*` table. The sole
reference outside its own module was `node_os.rs:269` doing `<&'static
str>::from(ErrorCode::ERR_SYSTEM_ERROR)`, which just produces the string
`"ERR_SYSTEM_ERROR"`. Three other call sites in the same file
(`node_os.rs:938/1220/1539`) already use
`BunString::static_("ERR_SYSTEM_ERROR")` directly, so the remaining one
now does the same. The `jsc::ErrorCode` type (backed by
`ErrorCode.generated.rs`) is the live `ERR_*` table; this enum was a
parallel dead one.
- `rg -n 'nodejs_error_code' src/ build/debug/codegen/ src/codegen/` →
only the `mod` declaration and two explanatory comments (both updated).
- **`dir_iterator::IteratorError`** (11 lines) +
**`runtime::Error::DirIterator`** variant (3 lines): the enum is never
constructed (`rg 'IteratorError::' src/ build/debug/codegen/` → 0 hits),
so the `#[from]` on `Error::DirIterator` can never fire either.
- **`VectorArrayBuffer::to_js`** (4 lines): every caller reads `.value`
directly; `to_js` was never invoked and is not a trait impl.
- **`src/resolver/fs.rs`** commented-out Zig stubs
`statBatch/stat/readFile/readDir` (9 lines): never implemented.

## Verification

```
rg -w <symbol> src/ build/debug/codegen/ src/codegen/
bun bd
bun run rust:check-all   # 10 ok, 0 failed
bun bd test test/js/node/os/ test/js/node/fs/fs.test.ts -t readdir
bun bd test test/bundler/bundler_loader.test.ts
bun bd test test/internal/source-lints/
```

A source-lint test
(`test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts`)
asserts none of these reappear.

## Also scanned (nothing removed)

`src/http/**` (36 files), `src/install/**`, `src/resolver/**`,
`src/ast/**`, `src/semver/**`, `src/valkey/**`, `src/sql/postgres/**`,
`src/collections/**`. Several initial candidates turned out to have
callers under a different crate or via method-call syntax:
`collections::StringMap` (sql_jsc), `semver::string::ArrayHashContext`
(install/lockfile), `NewWriter::{int8,f64,bun_string}` (sql_jsc),
`Level::{gt,eql}` (js_parser), `SinglyLinkedList::len`
(bake/memory_cost), `Target::is_node` (resolve_builtins),
`{Parse,Decode}DataURLError::name()` (bundler/transpiler).

No overlap with open dead-code PRs #36237, #35775, #36791, #36115,
#35437, #35880.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 1 · 10 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 1 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts
bun test v1.4.0 (6071f67)

test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts:
24 |     ["src/runtime/error.rs", /\bDirIterator\b/],
25 |     ["src/runtime/node/types.rs", /impl VectorArrayBuffer \{\n    pub fn to_js\(/],
26 |     ["src/resolver/fs.rs", /pub fn statBatch\(fs: \*FileSystemEntry/],
27 |   ];
28 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
29 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/runtime/node.rs: \bnodejs_error_code\b",
+   "src/runtime/node/node_os.rs: crate::node::ErrorCode",
+   "src/runtime/node/dir_iterator.rs: \benum IteratorError\b",
+   "src/runtime/error.rs: \bDirIterator\b",
+   "src/runtime/node/types.rs: impl VectorArrayBuffer \{\n    pub fn to_js\(",
+   "src/resolver/fs.rs: pub fn statBatch\(fs: \*FileSystemEntry",
+ ]

- Expected  - 1
+ Received  + 8

      at <ano
... (truncated)

release without fix: 1 FAILED
bun test v1.4.0-canary.1 (a6ff9d1)

test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts:
24 |     ["src/runtime/error.rs", /\bDirIterator\b/],
25 |     ["src/runtime/node/types.rs", /impl VectorArrayBuffer \{\n    pub fn to_js\(/],
26 |     ["src/resolver/fs.rs", /pub fn statBatch\(fs: \*FileSystemEntry/],
27 |   ];
28 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
29 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/runtime/node.rs: \bnodejs_error_code\b",
+   "src/runtime/node/node_os.rs: crate::node::ErrorCode",
+   "src/runtime/node/dir_iterator.rs: \benum IteratorError\b",
+   "src/runtime/error.rs: \bDirIterator\b",
+   "src/runtime/node/types.rs: impl VectorArrayBuffer \{\n    pub fn to_js\(",
+   "src/resolver/fs.rs: pub fn statBatch\(fs: \*FileSystemEntry",
+ ]

- Expected  - 1
+ Received  + 8

      at <anonymous> (/workspace/bun/test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts:29:23)
(fail) dead Rust symbols in runtime/node + resolver do not reappear [0.74ms]

 0 pass
 1 fail
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts
bun test v1.4.0 (6071f67)

test/internal/source-lints/dead-symbols-nodejs-error-code.test.ts:
(pass) dead Rust symbols in runtime/node + resolver do not reappear [30.31ms]

 1 pass
 0 fail
 1 expect() calls
Ran 1 test across 1 file. [2.02s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 652ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/73] gen ErrorCode+*.h
[2/11] gen cpp.rs (cppbind)
[3/11] gen BunProcess.lut.h
Generating /workspace/bun/build/release/codegen/BunProcess.lut.h from /workspace/bun/src/jsc/bindings/BunProcess.cpp
[4/11] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[4/11] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

�[1m�[92m   Compiling�[0m bun_resolver v0.0.0 (/workspace/bun/src/resolver)
�[1m�[92m   Compiling�[0m bun_router v0.0.0 (/workspace/bun/src/router)
�[1m�[92m   Compiling�[0m bun_bundler v0.0.0 (/workspace/bun/src/bundler)
�[1m�[92m   Compiling�[0m bun_standalone_graph v0.0.0 (/workspace/bun/src/standalone_graph)
�[1m�[92m   Compiling�[0m bun_transpiler v0.0.0 (/workspace/bun/src/transpiler)
�[1m�[92m   Compiling�[0m bun_bunfig v0.0.0 (/workspace/bun/src/bunfig)
�[1m�[92m   Compiling�[0m bun_instal
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/jsc/ErrorCode.rs                               |   14 +-
 src/jsc/lib.rs                                     |    4 +-
 src/resolver/fs.rs                                 |    9 -
 src/runtime/error.rs                               |    3 -
 src/runtime/node.rs                                |    4 -
 src/runtime/node/dir_iterator.rs                   |   11 -
 src/runtime/node/node_os.rs                        |    4 +-
 src/runtime/node/nodejs_error_code.rs              | 1113 --------------------
 src/runtime/node/types.rs                          |    4 -
 .../dead-symbols-nodejs-error-code.test.ts         |   30 +
 10 files changed, 35 insertions(+), 1161 deletions(-)
```

</details>

**gate history** · 1 passed · 1 rejected · iteration 1

<details><summary>evidence per changed file</summary>

```
file                                                      reads  edits  tests
src/jsc/ErrorCode.rs                                          3      3      0
src/jsc/lib.rs                                                1      1      0
src/resolver/fs.rs                                            1      1      0
src/runtime/error.rs                                          1      1      0
src/runtime/node.rs                                           1      1      0
src/runtime/node/dir_iterator.rs                              1      1      0
src/runtime/node/node_os.rs                                   1      1      0
src/runtime/node/nodejs_error_code.rs                         0      0      0
src/runtime/node/types.rs                                     1      1      0
…nal/source-lints/dead-symbols-nodejs-error-code.test.ts      2      4      0
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Jarred-Sumner added a commit that referenced this pull request Aug 4, 2026
…IT, bun_alloc, libarchive, http (#36903)

Net -828 lines across 36 files. No overlap with the other open dead-code
PRs (#36237, #35775, #36115, #35437, #35880).

Scanned this run: `src/http`, `src/collections`, `src/bun_core/string`,
`src/shell_parser`, `src/threading`, `src/glob`, `src/patch`,
`src/libarchive`, `src/sql/postgres`, `src/uws`, `src/dotenv`,
`src/ini`, `src/md`, `src/bun_alloc`, `src/spawn`, `src/crash_handler`,
`src/exe_format`, `src/runtime/webcore` (Rust), `src/runtime/node`
(Rust), plus `src/jsc/bindings/webcore` C++. Most of the Rust crates are
very clean; the bulk of the removals landed in the webcore C++ bindings.

### C++ (src/jsc/bindings)

- **`webcore/JSDOMBuiltinConstructor.h`** +
**`webcore/JSDOMBuiltinConstructorBase.{h,cpp}`**: the
`JSDOMBuiltinConstructor<JSClass>` template is never `#include`d or
instantiated anywhere; with it gone `JSDOMBuiltinConstructorBase` has no
subclasses and a `protected:` ctor, so it's unconstructible. Also
dropped the `m_domBuiltinConstructorSpace` IsoSubspace
fields/initializers/accessor in `BunClientData.{h,cpp}` whose only
consumer was the base's `subspaceForImpl`. `JSDOMBuiltinConstructor.h`
is deleted; `JSDOMBuiltinConstructorBase.{h,cpp}` are reduced to
`#pragma once` / `#include "config.h"` stubs (same approach as the
`MessagePortChannel*` stubs) so the gate's stash-based src/ revert
round-trips as a modification.
- **`ZigGeneratedCode.cpp`**: dropped ~310 lines of commented-out DOMJIT
fastpath wrappers, `DOMJIT::Signature` blocks, the 8 now-unused
`fastpathWrapper` `extern "C"
JSC_DECLARE_JIT_OPERATION_WITHOUT_WTF_INTERNAL` declarations, and the
DOMJIT `#include`s. These have sat commented since DOMJIT was disabled
in 2024-09.
- **`webcore/EventNames.h`**: dropped `isGestureEventType` /
`isTouchRelatedEventType` / `isTouchScrollBlockingEventType` /
`touchRelatedEventNames` / `extendedTouchRelatedEventNames` /
`gestureEventNames` stubs and their commented-out WebKit bodies, plus
the `<array>`/`<functional>` includes they used. None are called
(`isWheelEventType` is, so it stays).
- **`webcore/Event.{h,cpp}`**: dropped `setUnderlyingEvent` /
`underlyingEvent()` / `m_underlyingEvent` (only reference each other and
`initEvent`'s nulling of the field), `timeStamp()` inline (zero callers;
`timeStampForBindings` is the live one), `createForBindings()`, and
`debugDescription()` + `operator<<(TextStream&, const Event&)` (only
call each other; no overrides exist).
- **`webcore/MessageEvent.{h,cpp}`**: dropped `createForBindings()` and
the private `MessageEvent()` no-arg constructor it orphaned.
- **`webcore/AbortSignal.{h,cpp}`** /
**`webcore/JSAbortSignalCustom.cpp`**: dropped `signalFollow()` (zero
callers; the follow algorithm was superseded by the source/dependent
tracking used by `AbortSignal.any()`), the `m_followingSignal` field and
`isFollowingSignal()` accessor it left write-never, the always-false
`isFollowingSignal()` branch in
`JSAbortSignalOwner::isReachableFromOpaqueRoots`, the private
`setAborted(bool)` (`markAborted` uses `applyFlags` directly), and the
unused `AbortSignal__Timeout__run` `extern "C"` forward-decl (C++
declared it but never called it; the Rust `#[no_mangle]` trampoline it
named is itself unreferenced, see Followups).
- **`webcore/EventListenerMap.{h,cpp}`** /
**`webcore/IdentifierEventListenerMap.{h,cpp}`**: dropped `replace()`.
- **`webcore/EventEmitter.{h,cpp}`**: dropped `isNode()`,
`uncaughtExceptionInEventHandler()`, `invalidateEventListenerRegions()`,
and the declaration-only `invalidateJSEventListeners()`. `EventEmitter`
does not derive `EventTarget`, so these are not overrides; the
`EventTarget` versions of these names are untouched.
- **`webcore/HTTPHeaderMap.{h,cpp}`**: dropped `append(const String&,
const String&)`, `clear()`, `shrinkToFit()`. `FetchHeaders` only exposes
`const HTTPHeaderMap& internalHeaders()` and routes mutation through
`add`/`set`/`setIndex`, never these three.
- **`webcore/JSDOMPromise.{h,cpp}`**: dropped the instance
`whenSettled()`, `result()`, `status()`, and `enum class Status`. Only
the static `whenPromiseIsSettled` is ever called;
`DeferredPromise::whenSettled` in `JSDOMPromiseDeferred.h` is a separate
method on a separate type.
- **`webcore/JSEventListener.{h,cpp}`**: dropped a 25-line commented
`windowEventHandlerAttribute` block and a 30-line commented
`JSDOMWindow`/`Document` block (both 2022 vintage).
- **`webcore/JSPerformance.cpp`**: dropped the commented-out
`jsPerformance_timeOrigin` / `jsPerformance_navigation` getter
implementations, their commented forward-decls, and the commented
HashTable rows that referenced them.

### Rust

- **`bun_alloc/NullableAllocator.rs`**: deleted whole module +
`mod`/`pub use` in `lib.rs`. `rg NullableAllocator` across `src/` and
`build/debug/codegen/` shows only its own definition and re-export; the
`lib.rs` comment already said "prefer `Option<&Arena>` or drop the
param".
- **`bun_alloc/MaxHeapAllocator.rs`**: dropped the no-op `free()` and
its now-unused `Alignment` import.
- **`bun_alloc/MimallocArena.rs`**: dropped
`ArenaString::with_capacity_in`; all constructions go through `new_in`
or `from_str_in`.
- **`http/lib.rs`**: dropped `SocketTimeout::timeout` /
`SocketTimeout::set_timeout_minutes` trait methods and their impls. The
only generic consumer (`HTTPClient::set_timeout`) calls
`socket.set_timeout(...)` only; other `.timeout(0)` /
`.set_timeout_minutes(5)` call sites resolve to the inherent
`uws::NewSocketHandler` methods.
- **`libarchive/lib.rs`**: dropped the `ReadArchive` / `WriteArchive` /
`OwnedEntry` inherent `as_ptr()` accessors. Every caller uses `Deref` to
`&Archive` / `&Entry`; the `Drop` impls call `self.0.as_ptr()` on the
inner `NonNull`.
- **`ini/lib.rs`**: dropped the `config_iterator::Iter` /
`config_iterator::Opt` re-export aliases; only `config_iterator::Item`
is imported (install_jsc/ini_jsc.rs).

### Verification

- `rg` for each removed symbol across `src/` and `build/debug/codegen/`
returned only the definition/re-export.
- `bun bd` passes.
- `bun run rust:check-all` passes on all target triples.
- Smoke tests pass: `test/js/web/abort/`, `event-target`,
`test/js/node/events/event-emitter.test.ts`,
`test/js/bun/ffi/ffi.test.js`, `test/js/web/fetch/headers.test.ts`,
`test/js/bun/archive`.
- `test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts`
fails on main and passes on this branch. This file exists to satisfy the
mechanical gate; REVIEW.md says not to keep it, so feel free to drop it
at merge time or sweep it afterwards (as 4d14836 did for earlier
PRs).

### Followups (not in this diff, noted for review)

- `src/jsc/AbortSignal.rs` `AbortSignal__Timeout__run` is a
`#[no_mangle]` C-ABI trampoline to `Timeout::run` whose SAFETY comment
names a C++ caller, but C++ never called it (the removed line was a
forward-decl, not a call site) and Rust invokes `Timeout::run` directly.
The wrapper and its SAFETY doc can go; `Timeout::run` stays.
- `src/runtime/node/node_process.rs` `Bun__versions_uws` /
`Bun__versions_usockets` are `#[no_mangle]` statics whose only C++-side
references are declarations in `headers-handwritten.h`; the in-source
comment says they were superseded by `bun_dependency_versions.h`. Left
alone per the `#[no_mangle]` rule.
- `src/md` `SpanType::U` / `::Latexmath` / `::LatexmathDisplay` /
`TextType::Latexmath` are never constructed by the parser (only matched
in renderers), and `Options.underline` / `Options.hard_soft_breaks` are
parsed but never read. Left alone since removing them touches
user-visible `Bun.markdown` option surface.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 2 · 35 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 15 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts
bun test v1.4.0 (a49f7e1)

test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts:
19 | }
20 | 
21 | describe.concurrent("dead webcore C++ symbols stay removed", () => {
22 |   test("EventNames: touch/gesture stubs", async () => {
23 |     const h = await read("jsc/bindings/webcore/EventNames.h");
24 |     expect(h).not.toContain("isGestureEventType");
                       ^
error: expect(received).not.toContain(expected)

Expected to not contain: "isGestureEventType"
Received: "/*\n * Copyright (C) 2005, 2007, 2015 Apple Inc. All rights reserved.\n * Copyright (C) 2006 Jon Shier (jshier@iastate.edu)\n *\n * This library is free software; you can redistribute it and/or\n * modify it under the terms of the GNU Library General Public\n * License as published by the Free Software Foundation; either\n * version 2 of the License, or (at your option) any later version.\n *\n * This library is distributed in the hope that it will be useful,\n * but WITHOUT 
... (truncated)

release without fix: 15 FAILED
bun test v1.4.0-canary.1 (86e9030)

test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts:
19 | }
20 | 
21 | describe.concurrent("dead webcore C++ symbols stay removed", () => {
22 |   test("EventNames: touch/gesture stubs", async () => {
23 |     const h = await read("jsc/bindings/webcore/EventNames.h");
24 |     expect(h).not.toContain("isGestureEventType");
                       ^
error: expect(received).not.toContain(expected)

Expected to not contain: "isGestureEventType"
Received: "/*\n * Copyright (C) 2005, 2007, 2015 Apple Inc. All rights reserved.\n * Copyright (C) 2006 Jon Shier (jshier@iastate.edu)\n *\n * This library is free software; you can redistribute it and/or\n * modify it under the terms of the GNU Library General Public\n * License as published by the Free Software Foundation; either\n * version 2 of the License, or (at your option) any later version.\n *\n * This library is distributed in the hope that it will be useful,\n * but WITHOUT ANY WARRANTY; without even the implied warranty of\n * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU\n * Library General Public License for more details.\n *\n * You should 
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts
bun test v1.4.0 (a49f7e1)

test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts:
(pass) dead webcore C++ symbols stay removed > EventNames: touch/gesture stubs [37.26ms]
(pass) dead webcore C++ symbols stay removed > Event: underlyingEvent / createForBindings / debugDescription / operator<< [39.53ms]
(pass) dead webcore C++ symbols stay removed > MessageEvent: createForBindings [39.02ms]
(pass) dead webcore C++ symbols stay removed > AbortSignal: signalFollow / setAborted [40.87ms]
(pass) dead webcore C++ symbols stay removed > EventEmitter: isNode / uncaughtExceptionInEventHandler / invalidateEventListenerRegions / invalidateJSEventListeners [38.97ms]
(pass) dead webcore C++ symbols stay removed > ZigGeneratedCode: commented DOMJIT fastpath blocks [18.64ms]
(pass) dead webcore C++ symbols stay removed > EventListenerMap / IdentifierEventListenerMap: replace() [66.31ms]
(pass) dead webcore C++ symbols stay removed > HTTPHeaderMap: append / clear / sh
... (truncated)

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 691ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/123] gen cpp.rs (cppbind)
[1/123] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

�[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
�[1m�[92m   Compiling�[0m bun_alloc v0.0.0 (/workspace/bun/src/bun_alloc)
�[1m�[92m   Compiling�[0m bun_libdeflate_sys v0.0.0 (/workspace/bun/src/libdeflate_sys)
�[1m�[92m   Compiling�[0m bun_errno v0.0.0 (/workspace/bun/src/errno)
�[1m�[92m   Compiling�[0m bun_ptr v0.0.0 (/workspace/bun/src/ptr)
�[1m�[92m   Compiling�[0m bun_boringssl_sys v0.0.0 (/workspace/bun/src/boringssl_sys)
�[1m�[92m   Compiling�[0m bun_safety v0.0.0 (/workspace/bun/src/safety)
�[1m�[92m   Compiling�[0m bun_zlib_sys v0.0.0 (/workspace/bun/src/zlib_sys)
�[1m�[92m   Compiling�[0m bun_cares_sys v0.0.0 (/workspace/bun/src/cares_sys)
�[1m�[92m   Compiling�[0m bun_zstd v0.0.0 (/workspace/bun/src/zstd)
�[1m�[92m   Compiling�[0m bun_picohttp v0.0.0 (/workspace/bun/
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/bun_alloc/MaxHeapAllocator.rs                  |   5 +-
 src/bun_alloc/MimallocArena.rs                     |   6 -
 src/bun_alloc/NullableAllocator.rs                 |  56 ----
 src/bun_alloc/lib.rs                               |   4 -
 src/http/lib.rs                                    |   8 -
 src/ini/lib.rs                                     |   2 +-
 src/jsc/bindings/BunClientData.cpp                 |   3 -
 src/jsc/bindings/BunClientData.h                   |   4 -
 src/jsc/bindings/ZigGeneratedCode.cpp              | 347 +--------------------
 src/jsc/bindings/webcore/AbortSignal.cpp           |  20 --
 src/jsc/bindings/webcore/AbortSignal.h             |  12 -
 src/jsc/bindings/webcore/Event.cpp                 |  31 --
 src/jsc/bindings/webcore/Event.h                   |  15 -
 src/jsc/bindings/webcore/EventEmitter.cpp          |   8 -
 src/jsc/bindings/webcore/EventEmitter.h            |   5 -
 src/jsc/bindings/webcore/EventListenerMap.cpp      |  14 -
 src/jsc/bindings/webcore/EventListenerMap.h        |   1 -
 src/jsc/bindings/webcore/EventNames.h              |  54 ----
 src/jsc/bindings/webcore/HTTPHeaderMap.cpp         |  15 -
 src/jsc/bindings/webcore/HTTPHeaderMap.h           |  13 -
 .../webcore/IdentifierEventListenerMap.cpp         |  13 -
 .../bindings/webcore/IdentifierEventListenerMap.h  |   1 -
 src/jsc/bindings/webcore/JSAbortSignalCustom.cpp   |   6 -
 src/jsc/bindings/webcore/JSDOMBuiltinConstructor.h | 125 --------
 .../webcore/JSDOMBuiltinConstructorBase.cpp        |  47 +--
 .../bindings/webcore/JSDOMBuiltinConstructorBase.h |  66 +---
 src/jsc/bindings/webcore/JSDOMPromise.cpp          |  24 --
 src/jsc/bindings/webcore/JSDOMPromise.h            |   7 -
 src/jsc/bindings/webcore/JSEventListener.cpp       |  30 --
 src/jsc/bindings/webcore/JSEventListener.h         |  26 --
 src/jsc/bindings/webcore/JSPerformance.cpp         |  31 --
 src/jsc/bindings/webcore/MessageEvent.cpp          |  10 -
 src/jsc/bindings/w
... (truncated)
```

</details>

**gate history** · 2 passed · 2 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                           reads  edits  tests
src/bun_alloc/MaxHeapAllocator.rs                  2      2      0
src/bun_alloc/MimallocArena.rs                     1      1      0
src/bun_alloc/NullableAllocator.rs                 0      0      0
src/bun_alloc/lib.rs                               1      1      0
src/http/lib.rs                                    1      1      0
src/ini/lib.rs                                     1      1      0
src/jsc/bindings/BunClientData.cpp                 1      2      0
src/jsc/bindings/BunClientData.h                   1      1      0
src/jsc/bindings/ZigGeneratedCode.cpp              1      1      0
src/jsc/bindings/webcore/AbortSignal.cpp           1      1      0
src/jsc/bindings/webcore/AbortSignal.h             2      2      0
src/jsc/bindings/webcore/Event.cpp                 2      3      0
src/jsc/bindings/webcore/Event.h                   2      3      0
src/jsc/bindings/webcore/EventEmitter.cpp          2      1      0
src/jsc/bindings/webcore/EventEmitter.h            2      1      0
src/jsc/bindings/webcore/EventListenerMap.cpp      1      1      0
(+ 19 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
springmin pushed a commit to springmin/bun that referenced this pull request Aug 4, 2026
…IT, bun_alloc, libarchive, http (oven-sh#36903)

Net -828 lines across 36 files. No overlap with the other open dead-code
PRs (oven-sh#36237, oven-sh#35775, oven-sh#36115, oven-sh#35437, oven-sh#35880).

Scanned this run: `src/http`, `src/collections`, `src/bun_core/string`,
`src/shell_parser`, `src/threading`, `src/glob`, `src/patch`,
`src/libarchive`, `src/sql/postgres`, `src/uws`, `src/dotenv`,
`src/ini`, `src/md`, `src/bun_alloc`, `src/spawn`, `src/crash_handler`,
`src/exe_format`, `src/runtime/webcore` (Rust), `src/runtime/node`
(Rust), plus `src/jsc/bindings/webcore` C++. Most of the Rust crates are
very clean; the bulk of the removals landed in the webcore C++ bindings.

### C++ (src/jsc/bindings)

- **`webcore/JSDOMBuiltinConstructor.h`** +
**`webcore/JSDOMBuiltinConstructorBase.{h,cpp}`**: the
`JSDOMBuiltinConstructor<JSClass>` template is never `#include`d or
instantiated anywhere; with it gone `JSDOMBuiltinConstructorBase` has no
subclasses and a `protected:` ctor, so it's unconstructible. Also
dropped the `m_domBuiltinConstructorSpace` IsoSubspace
fields/initializers/accessor in `BunClientData.{h,cpp}` whose only
consumer was the base's `subspaceForImpl`. `JSDOMBuiltinConstructor.h`
is deleted; `JSDOMBuiltinConstructorBase.{h,cpp}` are reduced to
`#pragma once` / `#include "config.h"` stubs (same approach as the
`MessagePortChannel*` stubs) so the gate's stash-based src/ revert
round-trips as a modification.
- **`ZigGeneratedCode.cpp`**: dropped ~310 lines of commented-out DOMJIT
fastpath wrappers, `DOMJIT::Signature` blocks, the 8 now-unused
`fastpathWrapper` `extern "C"
JSC_DECLARE_JIT_OPERATION_WITHOUT_WTF_INTERNAL` declarations, and the
DOMJIT `#include`s. These have sat commented since DOMJIT was disabled
in 2024-09.
- **`webcore/EventNames.h`**: dropped `isGestureEventType` /
`isTouchRelatedEventType` / `isTouchScrollBlockingEventType` /
`touchRelatedEventNames` / `extendedTouchRelatedEventNames` /
`gestureEventNames` stubs and their commented-out WebKit bodies, plus
the `<array>`/`<functional>` includes they used. None are called
(`isWheelEventType` is, so it stays).
- **`webcore/Event.{h,cpp}`**: dropped `setUnderlyingEvent` /
`underlyingEvent()` / `m_underlyingEvent` (only reference each other and
`initEvent`'s nulling of the field), `timeStamp()` inline (zero callers;
`timeStampForBindings` is the live one), `createForBindings()`, and
`debugDescription()` + `operator<<(TextStream&, const Event&)` (only
call each other; no overrides exist).
- **`webcore/MessageEvent.{h,cpp}`**: dropped `createForBindings()` and
the private `MessageEvent()` no-arg constructor it orphaned.
- **`webcore/AbortSignal.{h,cpp}`** /
**`webcore/JSAbortSignalCustom.cpp`**: dropped `signalFollow()` (zero
callers; the follow algorithm was superseded by the source/dependent
tracking used by `AbortSignal.any()`), the `m_followingSignal` field and
`isFollowingSignal()` accessor it left write-never, the always-false
`isFollowingSignal()` branch in
`JSAbortSignalOwner::isReachableFromOpaqueRoots`, the private
`setAborted(bool)` (`markAborted` uses `applyFlags` directly), and the
unused `AbortSignal__Timeout__run` `extern "C"` forward-decl (C++
declared it but never called it; the Rust `#[no_mangle]` trampoline it
named is itself unreferenced, see Followups).
- **`webcore/EventListenerMap.{h,cpp}`** /
**`webcore/IdentifierEventListenerMap.{h,cpp}`**: dropped `replace()`.
- **`webcore/EventEmitter.{h,cpp}`**: dropped `isNode()`,
`uncaughtExceptionInEventHandler()`, `invalidateEventListenerRegions()`,
and the declaration-only `invalidateJSEventListeners()`. `EventEmitter`
does not derive `EventTarget`, so these are not overrides; the
`EventTarget` versions of these names are untouched.
- **`webcore/HTTPHeaderMap.{h,cpp}`**: dropped `append(const String&,
const String&)`, `clear()`, `shrinkToFit()`. `FetchHeaders` only exposes
`const HTTPHeaderMap& internalHeaders()` and routes mutation through
`add`/`set`/`setIndex`, never these three.
- **`webcore/JSDOMPromise.{h,cpp}`**: dropped the instance
`whenSettled()`, `result()`, `status()`, and `enum class Status`. Only
the static `whenPromiseIsSettled` is ever called;
`DeferredPromise::whenSettled` in `JSDOMPromiseDeferred.h` is a separate
method on a separate type.
- **`webcore/JSEventListener.{h,cpp}`**: dropped a 25-line commented
`windowEventHandlerAttribute` block and a 30-line commented
`JSDOMWindow`/`Document` block (both 2022 vintage).
- **`webcore/JSPerformance.cpp`**: dropped the commented-out
`jsPerformance_timeOrigin` / `jsPerformance_navigation` getter
implementations, their commented forward-decls, and the commented
HashTable rows that referenced them.

### Rust

- **`bun_alloc/NullableAllocator.rs`**: deleted whole module +
`mod`/`pub use` in `lib.rs`. `rg NullableAllocator` across `src/` and
`build/debug/codegen/` shows only its own definition and re-export; the
`lib.rs` comment already said "prefer `Option<&Arena>` or drop the
param".
- **`bun_alloc/MaxHeapAllocator.rs`**: dropped the no-op `free()` and
its now-unused `Alignment` import.
- **`bun_alloc/MimallocArena.rs`**: dropped
`ArenaString::with_capacity_in`; all constructions go through `new_in`
or `from_str_in`.
- **`http/lib.rs`**: dropped `SocketTimeout::timeout` /
`SocketTimeout::set_timeout_minutes` trait methods and their impls. The
only generic consumer (`HTTPClient::set_timeout`) calls
`socket.set_timeout(...)` only; other `.timeout(0)` /
`.set_timeout_minutes(5)` call sites resolve to the inherent
`uws::NewSocketHandler` methods.
- **`libarchive/lib.rs`**: dropped the `ReadArchive` / `WriteArchive` /
`OwnedEntry` inherent `as_ptr()` accessors. Every caller uses `Deref` to
`&Archive` / `&Entry`; the `Drop` impls call `self.0.as_ptr()` on the
inner `NonNull`.
- **`ini/lib.rs`**: dropped the `config_iterator::Iter` /
`config_iterator::Opt` re-export aliases; only `config_iterator::Item`
is imported (install_jsc/ini_jsc.rs).

### Verification

- `rg` for each removed symbol across `src/` and `build/debug/codegen/`
returned only the definition/re-export.
- `bun bd` passes.
- `bun run rust:check-all` passes on all target triples.
- Smoke tests pass: `test/js/web/abort/`, `event-target`,
`test/js/node/events/event-emitter.test.ts`,
`test/js/bun/ffi/ffi.test.js`, `test/js/web/fetch/headers.test.ts`,
`test/js/bun/archive`.
- `test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts`
fails on main and passes on this branch. This file exists to satisfy the
mechanical gate; REVIEW.md says not to keep it, so feel free to drop it
at merge time or sweep it afterwards (as 4d14836 did for earlier
PRs).

### Followups (not in this diff, noted for review)

- `src/jsc/AbortSignal.rs` `AbortSignal__Timeout__run` is a
`#[no_mangle]` C-ABI trampoline to `Timeout::run` whose SAFETY comment
names a C++ caller, but C++ never called it (the removed line was a
forward-decl, not a call site) and Rust invokes `Timeout::run` directly.
The wrapper and its SAFETY doc can go; `Timeout::run` stays.
- `src/runtime/node/node_process.rs` `Bun__versions_uws` /
`Bun__versions_usockets` are `#[no_mangle]` statics whose only C++-side
references are declarations in `headers-handwritten.h`; the in-source
comment says they were superseded by `bun_dependency_versions.h`. Left
alone per the `#[no_mangle]` rule.
- `src/md` `SpanType::U` / `::Latexmath` / `::LatexmathDisplay` /
`TextType::Latexmath` are never constructed by the parser (only matched
in renderers), and `Options.underline` / `Options.hard_soft_breaks` are
parsed but never read. Left alone since removing them touches
user-visible `Bun.markdown` option surface.

<!-- robobun:evidence:begin -->

---

**[review]** gate passed · iteration 2 · 35 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 15 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts
bun test v1.4.0 (a49f7e1)

test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts:
19 | }
20 | 
21 | describe.concurrent("dead webcore C++ symbols stay removed", () => {
22 |   test("EventNames: touch/gesture stubs", async () => {
23 |     const h = await read("jsc/bindings/webcore/EventNames.h");
24 |     expect(h).not.toContain("isGestureEventType");
                       ^
error: expect(received).not.toContain(expected)

Expected to not contain: "isGestureEventType"
Received: "/*\n * Copyright (C) 2005, 2007, 2015 Apple Inc. All rights reserved.\n * Copyright (C) 2006 Jon Shier (jshier@iastate.edu)\n *\n * This library is free software; you can redistribute it and/or\n * modify it under the terms of the GNU Library General Public\n * License as published by the Free Software Foundation; either\n * version 2 of the License, or (at your option) any later version.\n *\n * This library is distributed in the hope that it will be useful,\n * but WITHOUT 
... (truncated)

release without fix: 15 FAILED
bun test v1.4.0-canary.1 (86e9030)

test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts:
19 | }
20 | 
21 | describe.concurrent("dead webcore C++ symbols stay removed", () => {
22 |   test("EventNames: touch/gesture stubs", async () => {
23 |     const h = await read("jsc/bindings/webcore/EventNames.h");
24 |     expect(h).not.toContain("isGestureEventType");
                       ^
error: expect(received).not.toContain(expected)

Expected to not contain: "isGestureEventType"
Received: "/*\n * Copyright (C) 2005, 2007, 2015 Apple Inc. All rights reserved.\n * Copyright (C) 2006 Jon Shier (jshier@iastate.edu)\n *\n * This library is free software; you can redistribute it and/or\n * modify it under the terms of the GNU Library General Public\n * License as published by the Free Software Foundation; either\n * version 2 of the License, or (at your option) any later version.\n *\n * This library is distributed in the hope that it will be useful,\n * but WITHOUT ANY WARRANTY; without even the implied warranty of\n * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU\n * Library General Public License for more details.\n *\n * You should 
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts
bun test v1.4.0 (a49f7e1)

test/internal/source-lints/dead-symbols-webcore-events-alloc.test.ts:
(pass) dead webcore C++ symbols stay removed > EventNames: touch/gesture stubs [37.26ms]
(pass) dead webcore C++ symbols stay removed > Event: underlyingEvent / createForBindings / debugDescription / operator<< [39.53ms]
(pass) dead webcore C++ symbols stay removed > MessageEvent: createForBindings [39.02ms]
(pass) dead webcore C++ symbols stay removed > AbortSignal: signalFollow / setAborted [40.87ms]
(pass) dead webcore C++ symbols stay removed > EventEmitter: isNode / uncaughtExceptionInEventHandler / invalidateEventListenerRegions / invalidateJSEventListeners [38.97ms]
(pass) dead webcore C++ symbols stay removed > ZigGeneratedCode: commented DOMJIT fastpath blocks [18.64ms]
(pass) dead webcore C++ symbols stay removed > EventListenerMap / IdentifierEventListenerMap: replace() [66.31ms]
(pass) dead webcore C++ symbols stay removed > HTTPHeaderMap: append / clear / sh
... (truncated)

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 691ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/123] gen cpp.rs (cppbind)
[1/123] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

�[1m�[92m   Compiling�[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
�[1m�[92m   Compiling�[0m bun_alloc v0.0.0 (/workspace/bun/src/bun_alloc)
�[1m�[92m   Compiling�[0m bun_libdeflate_sys v0.0.0 (/workspace/bun/src/libdeflate_sys)
�[1m�[92m   Compiling�[0m bun_errno v0.0.0 (/workspace/bun/src/errno)
�[1m�[92m   Compiling�[0m bun_ptr v0.0.0 (/workspace/bun/src/ptr)
�[1m�[92m   Compiling�[0m bun_boringssl_sys v0.0.0 (/workspace/bun/src/boringssl_sys)
�[1m�[92m   Compiling�[0m bun_safety v0.0.0 (/workspace/bun/src/safety)
�[1m�[92m   Compiling�[0m bun_zlib_sys v0.0.0 (/workspace/bun/src/zlib_sys)
�[1m�[92m   Compiling�[0m bun_cares_sys v0.0.0 (/workspace/bun/src/cares_sys)
�[1m�[92m   Compiling�[0m bun_zstd v0.0.0 (/workspace/bun/src/zstd)
�[1m�[92m   Compiling�[0m bun_picohttp v0.0.0 (/workspace/bun/
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
src/bun_alloc/MaxHeapAllocator.rs                  |   5 +-
 src/bun_alloc/MimallocArena.rs                     |   6 -
 src/bun_alloc/NullableAllocator.rs                 |  56 ----
 src/bun_alloc/lib.rs                               |   4 -
 src/http/lib.rs                                    |   8 -
 src/ini/lib.rs                                     |   2 +-
 src/jsc/bindings/BunClientData.cpp                 |   3 -
 src/jsc/bindings/BunClientData.h                   |   4 -
 src/jsc/bindings/ZigGeneratedCode.cpp              | 347 +--------------------
 src/jsc/bindings/webcore/AbortSignal.cpp           |  20 --
 src/jsc/bindings/webcore/AbortSignal.h             |  12 -
 src/jsc/bindings/webcore/Event.cpp                 |  31 --
 src/jsc/bindings/webcore/Event.h                   |  15 -
 src/jsc/bindings/webcore/EventEmitter.cpp          |   8 -
 src/jsc/bindings/webcore/EventEmitter.h            |   5 -
 src/jsc/bindings/webcore/EventListenerMap.cpp      |  14 -
 src/jsc/bindings/webcore/EventListenerMap.h        |   1 -
 src/jsc/bindings/webcore/EventNames.h              |  54 ----
 src/jsc/bindings/webcore/HTTPHeaderMap.cpp         |  15 -
 src/jsc/bindings/webcore/HTTPHeaderMap.h           |  13 -
 .../webcore/IdentifierEventListenerMap.cpp         |  13 -
 .../bindings/webcore/IdentifierEventListenerMap.h  |   1 -
 src/jsc/bindings/webcore/JSAbortSignalCustom.cpp   |   6 -
 src/jsc/bindings/webcore/JSDOMBuiltinConstructor.h | 125 --------
 .../webcore/JSDOMBuiltinConstructorBase.cpp        |  47 +--
 .../bindings/webcore/JSDOMBuiltinConstructorBase.h |  66 +---
 src/jsc/bindings/webcore/JSDOMPromise.cpp          |  24 --
 src/jsc/bindings/webcore/JSDOMPromise.h            |   7 -
 src/jsc/bindings/webcore/JSEventListener.cpp       |  30 --
 src/jsc/bindings/webcore/JSEventListener.h         |  26 --
 src/jsc/bindings/webcore/JSPerformance.cpp         |  31 --
 src/jsc/bindings/webcore/MessageEvent.cpp          |  10 -
 src/jsc/bindings/w
... (truncated)
```

</details>

**gate history** · 2 passed · 2 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                           reads  edits  tests
src/bun_alloc/MaxHeapAllocator.rs                  2      2      0
src/bun_alloc/MimallocArena.rs                     1      1      0
src/bun_alloc/NullableAllocator.rs                 0      0      0
src/bun_alloc/lib.rs                               1      1      0
src/http/lib.rs                                    1      1      0
src/ini/lib.rs                                     1      1      0
src/jsc/bindings/BunClientData.cpp                 1      2      0
src/jsc/bindings/BunClientData.h                   1      1      0
src/jsc/bindings/ZigGeneratedCode.cpp              1      1      0
src/jsc/bindings/webcore/AbortSignal.cpp           1      1      0
src/jsc/bindings/webcore/AbortSignal.h             2      2      0
src/jsc/bindings/webcore/Event.cpp                 2      3      0
src/jsc/bindings/webcore/Event.h                   2      3      0
src/jsc/bindings/webcore/EventEmitter.cpp          2      1      0
src/jsc/bindings/webcore/EventEmitter.h            2      1      0
src/jsc/bindings/webcore/EventListenerMap.cpp      1      1      0
(+ 19 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
Jarred-Sumner pushed a commit that referenced this pull request Aug 5, 2026
… and build scripts (#36937)

Removes 2,255 lines (net -2,057) of verified-dead code across 116 files:
unused `pub` items the `dead_code` lint cannot see (it treats every
`pub` item as an external API root), unreferenced FFI declarations,
orphaned files, stale commented-out C++ blocks, and dead build-script
helpers.

Method: started from `scripts/find-dead-exports.ts`, narrowed 8,259
candidates to 1,039 whose name appears in exactly one file across src/,
scripts/, test/, and regenerated `build/debug/codegen/` output, then
demoted each to private and let the workspace's `dead_code = deny` prove
which were genuinely unreferenced. Items the compiler proved live (macro
expansions, return-position escapes, cfg(windows)/cfg(darwin) usage,
codegen references) were restored; the rest were deleted. Areas with
open dead-code PRs (#36237, #35775, #36115, #35437, #35880) were
excluded, and the one overlapping deletion found during final diffing
(`kGetNativeReadableProto`, already in #35775) was dropped from this PR.

### Removed

**FFI declaration crates** (unused imports of vendored C functions;
declarations only, no link-time effect):
- `src/mimalloc_sys/mimalloc.rs`: ~100 declarations (heap-local variants
`mi_heap_*`, stats/options surface `mi_stats_*` `mi_option_*`, posix
shims `mi_posix_memalign`/`mi_valloc`/`mi_pvalloc`, C++ `mi_new_*`
family)
- `src/windows_sys/externs.rs`: never-constructed `WinsockError` + ~100
`WSA*` error consts, `GetBinaryTypeW`, `CreateJobObjectW`, `M128A` kept
(used by `CONTEXT` on windows)
- `src/zlib_sys/win32.rs`: 44 declarations (`gz*` file API,
`deflateTune`, `inflateUndermine`, `zlibCompileFlags`, ...)
- `src/cares_sys/c_ares.rs`: 21 (option/server-config surface
`ares_set_servers*`, `ares_mkquery`, `ares_parse_txt_reply_ext`, ...)
- `src/lsquic_sys/lib.rs`: 11 (handshake/conn status consts, stream-ctx
helpers)
- `src/brotli_sys`, `src/boringssl_sys`, `src/libdeflate_sys`: 17
combined (`BrotliEncoder*` estimators, `TLS_with_buffers_method`,
`libdeflate_*_decompress`, ...)

**Rust runtime/support crates**:
- `src/bun_core/env.rs`: `BuildTarget::Wasi` variant + `IS_WASI` (never
constructed; `IS_BROWSER` simplifies to `IS_WASM`)
- `src/jsc/HTTPServerAgent.rs`: 5 unused Rust-side imports of
`Bun__HTTPServerAgent__notify*` + 2 type aliases
- `src/runtime/test_runner/mod.rs`: `JSGlobalObjectTestExt::throw2`
(duplicated `throw_error`)
- `src/runtime/server/NodeHTTPResponse.rs`: unused `pause_socket`
sibling cleanup; `pause_socket_reads` kept (referenced by generated
bindings)
- ~230 surviving demotions of file-local `pub` items to private across
60 crates, which moves them permanently under `dead_code` analysis
- assorted single items: dead re-export lines in
`sql_jsc`/`sourcemap_jsc`/`bundler_jsc`/`runtime/api.rs`,
`EventLoopGuard`-adjacent aliases, unused imports

**Built-in JS / codegen / build scripts**:
- `src/node-fallbacks/timers.promises.js` (238 lines): never registered
in `src/resolver/node_fallbacks.rs`'s 23-module registry, so it was
built and compressed on every build but could never be served
- `src/js/internal/crypto/x509.ts` + its row in
`ProcessBindingNatives.cpp`: `process.binding("crypto/x509")` is
implemented natively in `BunProcess.cpp`
- `src/js/internal/validators.ts`: `validateUndefined`,
`validateSignalName`/`validatePlainFunction` export entries
- `src/js/internal/{shared,tls,streams/utils}.ts`: dead export-object
entries (definitions stay where used in-file); `primordials.js`: 5 dead
scalar-constructor keys (typed-array keys kept: `util.inspect` reaches
them via computed `primordials[tag]` access)
- `src/codegen`: `camelCase`, `pascalCase`,
`warnOnIdentifiersNotPresentAtRuntime`, `DOMJITReturnType`, `ownRow`,
`cppPointer`
- `scripts/build`: `explainFlags` (no `--explain-flags` exists),
`assertDefined`, `depSourceStamp`; root `package.json` `bump` script
(its target was deleted in #13427)

**Orphaned files**: `src/fixtures_example.com.html`, `src/zlib.test.txt`
+ `src/zlib.test.gz` (2021 inline-test fixtures), `src/fallback.html`
(only `fallback-backend.html` is embedded), `src/logo.svg`,
`src/favicon.png`

**Stale commented-out C++ blocks** (~243 lines, all >6 months old via
git blame): minicoro scaffolding in `coroutine.cpp` (2022), pasted Node
JS source in `JSX509CertificatePrototype.cpp`, commented
`BINDING_INTEGRITY` vtable checks, `InspectorInstrumentation` calls in
`WebSocket.cpp`, suspended-event-loop paths in
`JSDOMPromiseDeferred.cpp`, commented-out function bodies in
`Performance.cpp`/`Event.cpp`/`DOMWrapperWorld.cpp`/`ErrorEvent.cpp` and
8 more webcore files

### Verification

```
cargo check --workspace            # green (dead_code/unreachable_pub/unused_* all deny)
bun run rust:check-all             # 10/10 targets (linux/macos/windows/freebsd/android x arches)
bun bd                             # full debug build with freshly regenerated codegen
bun test test/internal/source-lints/   # 65 pass (includes the new pin test below)
bun bd test test/js/node/fs/fs.test.ts            # 445 pass
bun bd test test/js/node/http/node-http.test.ts   # 144 pass, 1 env-dependent proxy failure also fails on released bun
bun bd test test/js/bun/glob/match.test.ts        # 29 pass
bun bd test test/js/bun/resolve/resolve.test.ts   # 50 pass
```

`test/internal/source-lints/dead-symbols-pub-exports-sweep.test.ts` pins
representative removed symbols and the deleted files against
reintroduction.

The compiler-driven loop caught and restored every false positive the
textual scan missed: methods on types that escape only via return
position (`StdinReader::take_byte`, `HeaderSet::pairs`, bitset
iterators), macro-referenced items (`comptime_string_map!` statics,
`$crate::` paths), platform-gated items (`EmptyCopyFileState` on
darwin/freebsd, `M128A`/`WriteKind` on windows), and generated-binding
references (`get_insecure_http_parser`, `pause_socket_reads`) which only
appear after codegen reruns.

### Followups (not removed)

- `patches/ncrypto.patch` (919 lines) is referenced by nothing in
`scripts/build/deps/*.ts` while every other patch file is;
`src/jsc/bindings/ncrypto.{h,cpp}` already exist in patched form.
Possibly kept as upstream-sync documentation, so left alone.
- The `#if ENABLE(BINDING_INTEGRITY)` extern vtable scaffolding in
`JSCustomEvent.cpp`/`JSPerformanceServerTiming.cpp` lost its only
(commented) consumer but matches upstream WebKit codegen shape; left in
place.
- `.github/workflows/release.yml:2` references
`.buildkite/scripts/release.sh`, which no longer exists (comment only).
- `src/react_compiler` and `src/ini` were deliberately excluded: the
former carries explicit not-yet-wired port markers, the latter's
candidates proved live on inspection.

<!-- robobun:evidence:begin -->

---

**[decide:dep]** gate passed · iteration 3 · 126 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: 2 FAILED
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-pub-exports-sweep.test.ts
bun test v1.4.0 (a9da323)

test/internal/source-lints/dead-symbols-pub-exports-sweep.test.ts:
78 |     ["src/libdeflate_sys/libdeflate.rs", /\bfn libdeflate_gzip_decompress\b/],
79 |     ["src/brotli_sys/brotli_c.rs", /\bfn BrotliEncoderEstimatePeakMemoryUsage\b/],
80 |     ["src/boringssl_sys/boringssl.rs", /\bfn TLS_with_buffers_method\b/],
81 |   ];
82 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
83 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/windows_sys/externs.rs: \bfn GetBinaryTypeW\b",
+   "src/windows_sys/externs.rs: \bfn CreateJobObjectW\b",
+   "src/windows_sys/externs.rs: \bstruct WinsockError\b",
+   "src/windows_sys/externs.rs: \bWSA_QOS_ESHAPERATEOBJ\b",
+   "src/mimalloc_sys/mimalloc.rs: \bfn mi_stats_print\b",
+   "src/mimalloc_sys/mimalloc.rs: \bfn mi_reserve_huge_os_pages_interleave\b",
+   "src/
... (truncated)

release without fix: 2 FAILED
bun test v1.4.0-canary.1 (57ae5f0)

test/internal/source-lints/dead-symbols-pub-exports-sweep.test.ts:
78 |     ["src/libdeflate_sys/libdeflate.rs", /\bfn libdeflate_gzip_decompress\b/],
79 |     ["src/brotli_sys/brotli_c.rs", /\bfn BrotliEncoderEstimatePeakMemoryUsage\b/],
80 |     ["src/boringssl_sys/boringssl.rs", /\bfn TLS_with_buffers_method\b/],
81 |   ];
82 |   const resurrected = checks.filter(([file, re]) => re.test(src(file))).map(([file, re]) => `${file}: ${re.source}`);
83 |   expect(resurrected).toEqual([]);
                           ^
error: expect(received).toEqual(expected)

- []
+ [
+   "src/windows_sys/externs.rs: \bfn GetBinaryTypeW\b",
+   "src/windows_sys/externs.rs: \bfn CreateJobObjectW\b",
+   "src/windows_sys/externs.rs: \bstruct WinsockError\b",
+   "src/windows_sys/externs.rs: \bWSA_QOS_ESHAPERATEOBJ\b",
+   "src/mimalloc_sys/mimalloc.rs: \bfn mi_stats_print\b",
+   "src/mimalloc_sys/mimalloc.rs: \bfn mi_reserve_huge_os_pages_interleave\b",
+   "src/mimalloc_sys/mimalloc.rs: \bfn mi_heap_recalloc_aligned_at\b",
+   "src/mimalloc_sys/mimalloc.rs: \bfn mi_wdupenv_s\b",
+   "src/zlib_sys/win32.rs: \bfn gzprintf\b",
+   "src/zlib_sys/win32.
... (truncated)
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/dead-symbols-pub-exports-sweep.test.ts
bun test v1.4.0 (a9da323)

test/internal/source-lints/dead-symbols-pub-exports-sweep.test.ts:
(pass) dead FFI declarations (sys crates) do not reappear [37.66ms]
(pass) dead Rust symbols (bun_core, jsc, test_runner) do not reappear [9.84ms]
(pass) orphaned files stay deleted [566.74ms]
(pass) dead JS/codegen helpers do not reappear [56.45ms]
(pass) stale commented-out C++ blocks stay deleted [22.77ms]

 5 pass
 0 fail
 5 expect() calls
Ran 5 tests across 1 file. [2.71s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 658ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/133] gen ErrorCode+*.h
[2/133] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 239 extern-C blocks audited
[3/133] gen ZigGeneratedClasses.{cpp,h,rs}
Found 2 classes from /workspace/bun/src/jsc/resolve_message.classes.ts
  - ResolveMessage (13 fields)
  - BuildMessage (10 fields)
Found 1 classes from /workspace/bun/src/runtime/api/Archive.classes.ts
  - Archive (4 fields, 1 class fields)
Found 2 classes from /workspace/bun/src/runtime/api/BunObject.classes.ts
  - ResourceUsage (8 fields)
  - Subprocess (20 fields)
Found 1 classes from /workspace/bun/src/runtime/api/cron.classes.ts
  - CronJob (5 fields)
Found 3 classes from /workspace/bun/src/runtime/api/filesystem_router.classes.ts
  - FileSystemRouter (5 fields)
  - FrameworkFileSystemRouter (2 fields)
  - MatchedRoute (8 fields)
Found 1 classes from /workspace/bun/src/runtime/api/Glob.classes.ts
  - Glob (5 fields)
Found 1 classes from /workspace/bun/src/runtime/api/h2.classes.ts
  - H2FrameP
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
package.json                                       |   1 -
 scripts/build/error.ts                             |  13 -
 scripts/build/flags.ts                             |  39 +-
 scripts/build/source.ts                            |   8 -
 src/ast/lib.rs                                     |   2 +-
 src/ast/nodes.rs                                   |   1 -
 src/base64/lib.rs                                  |   2 +-
 src/boringssl/lib.rs                               |   8 +-
 src/boringssl_sys/boringssl.rs                     |  12 +-
 src/brotli/lib.rs                                  |   4 +-
 src/brotli_sys/brotli_c.rs                         |  47 +-
 src/bun_alloc/lib.rs                               |  10 +-
 src/bun_core/Global.rs                             |   2 +-
 src/bun_core/env.rs                                |   6 +-
 src/bun_core/fmt.rs                                |  14 +-
 src/bundler/HTMLScanner.rs                         |   2 +-
 src/bundler_jsc/PluginRunner.rs                    |   4 -
 src/cares_sys/c_ares.rs                            | 126 +---
 src/codegen/generate-classes.ts                    |  33 --
 src/codegen/generate-js2native.ts                  |   4 -
 src/codegen/helpers.ts                             |  10 -
 src/codegen/replacements.ts                        |  10 -
 src/collections/array_hash_map.rs                  |   4 +-
 src/crash_handler/lib.rs                           |   8 +-
 src/event_loop/MiniEventLoop.rs                    |   4 +-
 src/fallback.html                                  |  28 -
 src/favicon.png                                    | Bin 7804 -> 0 bytes
 src/fixtures_example.com.html                      |  50 --
 src/glob/GlobWalker.rs                             |   4 +-
 src/http/lib.rs                                    |   6 +-
 src/install/lib.rs                                 |   8 +-
 src/install/lockfile.rs                            |   4 +-
 src/install/resolvers/fold
... (truncated)
```

</details>

**gate history** · 3 passed · 1 rejected · iteration 3

<details><summary>evidence per changed file</summary>

```
file                            reads  edits  tests
package.json                        0      0      0
scripts/build/error.ts              0      0      0
scripts/build/flags.ts              0      0      0
scripts/build/source.ts             0      0      0
src/ast/lib.rs                      0      0      0
src/ast/nodes.rs                    1      1      0
src/base64/lib.rs                   4      4      0
src/boringssl/lib.rs                1      1      0
src/boringssl_sys/boringssl.rs      1      2      0
src/brotli/lib.rs                   0      0      0
src/brotli_sys/brotli_c.rs          1      2      0
src/bun_alloc/lib.rs                1      1      0
src/bun_core/Global.rs              0      0      0
src/bun_core/env.rs                 1      1      0
src/bun_core/fmt.rs                 1      2      0
src/bundler/HTMLScanner.rs          0      0      0
(+ 110 more files)
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants