[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get - #54

Merged
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence
Aug 17, 2026
Merged

[Fix] avoid relying on indexOf's HasProperty+Get semantics, unlike includes's bare Get#54
ljharb merged 1 commit into
es-shims:mainfrom
rajanpanth:fix/proxy-has-trap-divergence

Conversation

@rajanpanth

Copy link
Copy Markdown
Contributor

Summary

The fast path delegates to $indexOf.apply(this, arguments) whenever searchElement isn't NaN/undefined and fromIndex is finite. For ordinary arrays this matches the spec's own includes algorithm, but indexOf's per-index step is HasProperty, then Get only if present, while includes's is a bare Get — per spec (Array.prototype.includes explicitly notes it "does not skip missing array elements, instead treating them as undefined", unlike indexOf).

For an exotic object whose has trap disagrees with its get trap, that difference is observable:

vartarget=[1,2,3,4,5];varproxy=newProxy(target,{has: function(){returnfalse;},get: function(t,k,r){returnReflect.get(t,k,r);}});Array.prototype.includes.call(proxy,3);// true (native, spec-correct)includes.call(proxy,3);// false (this shim, via the indexOf shortcut)

Changes

  • implementation.js: removed the indexOf-based fast path (and its now-unused $isNaN/$isFinite/$indexOf requires). The existing manual loop already implements the correct includes algorithm (bare Get via O[k], SameValueZero) and was only being skipped by this shortcut — so removing it is enough, no new logic needed.
  • test/tests.js: one new case (guarded by typeof Proxy === 'function', matching the pattern in is-callable's own tests) confirming a lying has trap doesn't hide an element that's still reachable via get.

Testing

  • Full suite: 117/117 passing (up from 114 — the new case runs against all three entry points, though only the direct implementation.js path is actually exercised by the bug, since index.js/shimmed.js prefer the native method when available).
  • Confirmed the new test fails on the prior code and passes with the fix.
  • eslint reports the same pre-existing linebreak-style/no-magic-numbers findings with and without this change (Windows checkout CRLF artifact + pre-existing style, unrelated) — no new lint issues, and one magic-number warning (-1) actually goes away since that line is removed.

…ike `includes`'s bare `Get`
The fast path delegated to $indexOf.apply(this, arguments) whenever
searchElement wasn't NaN/undefined and fromIndex was finite. For
ordinary arrays this is equivalent to the spec's own includes
algorithm, but indexOf's per-index step is "HasProperty, then Get
only if present" while includes's is a bare Get -- so for an exotic
object whose has trap disagrees with its get trap (e.g. a Proxy),
delegating to indexOf can silently miss an element that includes
must find.
Removed the optimization; the existing manual loop already
implements the correct includes algorithm (bare Get, SameValueZero)
and was only being skipped by this shortcut.
@codecov

codecovBot commented Aug 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.95%. Comparing base (62cae6d) to head (70ef118).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #54 +/- ##
==========================================
+ Coverage 96.36% 97.95% +1.59% 
==========================================
Files 5 5 Lines 55 49 -6 Branches 8 7 -1 ==========================================
- Hits 53 48 -5 + Misses 2 1 -1 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

The failing Node matrix appears unrelated to this change: all 15 failures stop during dependency setup before the test command runs. The shared workflow's determine-node-version step upgrades to npm 12.0.2, then
pm install --no-save @pkgjs/nv@0.2 semver@^7\ exits with \EALLOWGIT\ while resolving \ s-extra@github:reggi/node-fs-extra#enhanced\ (git package fetching is disabled). The remaining 135 checks pass, including coverage of every modified line.

@ljharb
ljharbforce-pushed the fix/proxy-has-trap-divergence branch from c7d26a3 to 70ef118CompareAugust 14, 2026 04:02

@ljharbljharb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've rebased this after pushing up fixes to the test suite.

Comment threadtest/tests.js Outdated
@rajanpanth

Copy link
Copy Markdown
ContributorAuthor

Thanks for rebasing this and pushing the test-suite fixes. I’ve pulled the updated branch context on my side — please let me know if you want any additional adjustments from me.

@ljharb
ljharb merged commit 70ef118 into es-shims:mainAug 17, 2026
540 of 550 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@rajanpanth@ljharb