Skip to content

Commit 26aa046

Browse files
committed
Merge branch 'main' of github.com:hurali97/react-native into feat/separate-library-plugin
2 parents 7f25183 + b4d57ab commit 26aa046

3,027 files changed

Lines changed: 134634 additions & 43405 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.clang-format-ignore‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
**/Pods/**
2+
**/build/**
3+
**/node_modules/**
4+
packages/react-native/React/I18n/FBXXHashUtils.h
5+
packages/react-native/ReactAndroid/src/main/jni/first-party/yogajni/**
6+
packages/react-native/ReactAndroid/src/main/jni/third-party/**
7+
packages/react-native/ReactCommon/**/platform/windows/third-party/**
8+
packages/react-native/ReactCommon/jsi/jsi/**
9+
packages/react-native/ReactCommon/yoga/**

‎.eslintrc.js‎

Lines changed: 9 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -15,21 +15,21 @@ module.exports = {
1515

1616
extends: ['@react-native'],
1717

18-
plugins: ['@react-native/monorepo', '@react-native/specs'],
18+
plugins: ['@react-native/monorepo', '@react-native/specs', 'import'],
1919

2020
overrides: [
2121
// overriding the JS config from @react-native/eslint-config to ensure
22-
// that we use hermes-eslint for all js files
22+
// that we use flow-eslint for all js files
2323
{
2424
files: ['*.js', '*.js.flow', '*.jsx'],
25-
parser: 'hermes-eslint',
25+
parser: 'flow-eslint',
2626
rules: {
2727
'@react-native/monorepo/sort-imports': 'warn',
2828
'eslint-comments/no-unlimited-disable': 'off',
2929
'ft-flow/require-valid-file-annotation': ['error', 'always'],
3030
'no-extra-boolean-cast': 'off',
3131
'no-void': 'off',
32-
// These rules are not required with hermes-eslint
32+
// These rules are not required with flow-eslint
3333
'ft-flow/define-flow-type': 'off',
3434
'ft-flow/use-flow-type': 'off',
3535
// Flow handles these checks for us, so they aren't required
@@ -44,6 +44,7 @@ module.exports = {
4444
files: ['*.js', '*.jsx', '*.ts', '*.tsx'],
4545
rules: {
4646
'@react-native/no-deep-imports': 'off',
47+
'import/enforce-node-protocol-usage': ['warn', 'always'],
4748
},
4849
},
4950
{
@@ -52,7 +53,7 @@ module.exports = {
5253
'./packages/react-native/src/**/*.{js,flow}',
5354
'./packages/assets-registry/registry.js',
5455
],
55-
parser: 'hermes-eslint',
56+
parser: 'flow-eslint',
5657
rules: {
5758
'@react-native/monorepo/no-commonjs-exports': 'warn',
5859
},
@@ -61,17 +62,14 @@ module.exports = {
6162
files: ['package.json'],
6263
parser: 'jsonc-eslint-parser',
6364
},
64-
{
65-
files: ['package.json'],
66-
rules: {
67-
'@react-native/monorepo/react-native-manifest': 'error',
68-
},
69-
},
7065
{
7166
files: ['flow-typed/**/*.js', 'packages/react-native/flow/**/*'],
7267
rules: {
7368
'@react-native/monorepo/valid-flow-typed-signature': 'error',
7469
'ft-flow/require-valid-file-annotation': 'off',
70+
// These libdefs are kept byte-identical across projects (see
71+
// flow-typed-sync-test), so they must not be migrated independently.
72+
'import/enforce-node-protocol-usage': 'off',
7573
'no-shadow': 'off',
7674
'no-unused-vars': 'off',
7775
quotes: 'off',

‎.expo-code-review/.gitignore‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
.runs/
Lines changed: 54 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,54 @@
1+
---
2+
description: Build graph, dependency, packaging, publishing, release, and CI workflow correctness.
3+
---
4+
5+
<!-- @ref glob:.github/workflows/** — CI and release workflow orchestration -->
6+
<!-- @ref glob:packages/react-native/**/*.podspec — CocoaPods package graph -->
7+
<!-- @ref glob:packages/react-native/**/CMakeLists.txt — CMake target graph -->
8+
<!-- @ref glob:packages/react-native/scripts/cocoapods/** — CocoaPods integration scripts -->
9+
<!-- @ref glob:packages/gradle-plugin/** — React Native Gradle Plugin -->
10+
<!-- @ref glob:scripts/releases/** — release tooling -->
11+
<!-- @ref glob:scripts/releases-ci/** — publishing and release CI tooling -->
12+
<!-- @ref packages/react-native/package.json — published React Native package contract -->
13+
# Build, release, and packaging correctness
14+
15+
Review dependency graphs and orchestration across Gradle, CMake, CocoaPods,
16+
Swift Package Manager, npm packaging, release scripts, and GitHub Actions.
17+
Security classification remains with the security reviewer.
18+
19+
## Own these defects
20+
21+
- A target, source, header, library, resource, or generated artifact is present
22+
in one supported build form but missing from another reachable build form.
23+
- Dependency scope, visibility, ordering, variant selection, or platform guards
24+
resolve the wrong artifact or omit a required transitive contract.
25+
- Version, package metadata, export, or release selection logic publishes the
26+
wrong files, package, tag, branch, or artifact for a concrete input.
27+
- Cache keys or restore paths reuse an artifact across incompatible platforms,
28+
toolchain versions, architectures, variants, or source revisions.
29+
- Workflow conditions, outputs, matrices, or job dependencies skip a required
30+
lane, run the wrong lane, or consume an output that cannot exist.
31+
- A subprocess result, partial failure, or retry path is ignored and allows a
32+
release or build to continue with incomplete output.
33+
34+
Compare all supported siblings before reporting parity: Android build variants,
35+
CocoaPods and Swift Package Manager, local and CI paths, source and prebuilt
36+
artifacts, and release channels. State the exact configuration that fails.
37+
38+
Use research only for a concrete external build-tool or package-manager contract.
39+
Repository scripts and pinned tool versions determine which part of that contract
40+
applies. Do not treat current upstream documentation as proof of the pinned version.
41+
42+
## Do not report
43+
44+
- Formatting, naming, or a convention observed in only one sibling.
45+
- A CI failure that an existing syntax checker reports without a separate
46+
orchestration defect.
47+
- Generic requests for more matrix coverage, caching, tests, or comments.
48+
- Native runtime behavior after a successfully built artifact starts; the native
49+
correctness reviewer owns it.
50+
- Credential exposure or execution of untrusted code with secrets; the security
51+
reviewer owns it.
52+
53+
Only report a concrete broken build, missing artifact, incorrect package, or
54+
misrouted workflow path caused by changed code.
Lines changed: 67 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,67 @@
1+
---
2+
description: Public API, Codegen, feature-flag, and cross-language contract correctness.
3+
alwaysRun: true
4+
---
5+
6+
<!-- @ref AGENTS.md#gotchas — authoritative API snapshot and generated-code rules -->
7+
<!-- @ref packages/react-native/index.js — runtime public JavaScript exports -->
8+
<!-- @ref packages/react-native/index.js.flow — typed public JavaScript exports -->
9+
<!-- @ref packages/react-native/ReactNativeApi.d.ts — committed JavaScript API snapshot -->
10+
<!-- @ref packages/react-native/package.json — published package and type entry points -->
11+
<!-- @ref packages/react-native/ReactAndroid/api/ReactAndroid.api — committed Android API snapshot -->
12+
<!-- @ref glob:scripts/cxx-api/** — C++ API snapshots and validator -->
13+
<!-- @ref glob:packages/react-native/**/Native*.js — candidate native-module specifications -->
14+
<!-- @ref glob:packages/react-native/**/*NativeComponent.js — candidate native-component specifications -->
15+
<!-- @ref packages/react-native/scripts/featureflags/ReactNativeFeatureFlags.config.js — feature-flag source of truth -->
16+
<!-- @ref packages/react-native/src/private/featureflags/__docs__/README.md#defining-feature-flags — generation rule -->
17+
<!-- @ref packages/react-native/src/private/featureflags/__docs__/README.md#setting-feature-flag-overrides — override ordering invariant -->
18+
# API and cross-language contracts
19+
20+
You are the cross-cutting reviewer. Own defects created by disagreement between
21+
files, languages, platforms, generated contracts, or public surfaces. Do not
22+
repeat isolated implementation findings from the JavaScript or native reviewers.
23+
24+
## Public API
25+
26+
Compare runtime exports, Flow exports, the committed JavaScript API snapshot,
27+
the package entry points, and relevant native API snapshots. Flag a reachable
28+
breaking change, wrong export target, incompatible type shape, or accidental
29+
public exposure. Distinguish stable API from explicitly private or unstable API.
30+
31+
Do not report only that a filtered generated snapshot was not updated. Infer
32+
compatibility from the changed source and visible contract.
33+
34+
## Codegen contracts
35+
36+
Treat JavaScript native-module and native-component specifications as sources
37+
for generated native contracts. Confirm a matching filename is actually a spec
38+
before applying this rule.
39+
40+
Trace changed method names, optionality, nullability, enums, events, callbacks,
41+
commands, and component props into their consumers. Flag mismatches that produce
42+
a wrong value, missing registration, runtime exception, or native crash. Do not
43+
ask authors to hand-edit generated output.
44+
45+
## Feature flags
46+
47+
The configuration file is the source of truth. Common flags must preserve one
48+
contract across JavaScript, C++, Objective-C++, Kotlin, and Java. Overrides must
49+
happen before the first cached access.
50+
51+
Trace changes to defaults, type, stage, removal, and call sites. Flag stale
52+
branches, incompatible defaults, or override ordering that makes the effective
53+
value depend on access order. Do not report only that generated files are absent.
54+
55+
## Cross-platform behavior
56+
57+
When a change crosses JavaScript, C++, Android, or Apple, identify the actual
58+
producer and every affected consumer. Report missing parity only when a reachable
59+
platform path now behaves incorrectly. Platform-specific behavior is not itself
60+
a defect.
61+
62+
Use research only when a concrete compatibility candidate depends on an external
63+
contract. A standard describes a target, not proof that React Native claims full
64+
support. Confirm that target in repository code or documentation before reporting.
65+
66+
Produce the shared `__overall_pr_risk__` handoff after assessing the complete
67+
change set.
Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
---
2+
description: Runtime correctness in React Native's Flow JavaScript, TypeScript, and Node execution paths.
3+
---
4+
5+
<!-- @ref AGENTS.md#repo-structure — identifies the JavaScript runtime and package surfaces -->
6+
<!-- @ref AGENTS.md#common-commands — identifies Flow, Jest, and Fantom validation -->
7+
<!-- @ref packages/react-native/index.js — runtime public API entry point -->
8+
<!-- @ref packages/react-native/index.js.flow — typed public API entry point -->
9+
# JavaScript and Flow correctness
10+
11+
Review logic inside JavaScript, Flow, TypeScript, and Node execution paths.
12+
13+
## Own these defects
14+
15+
- Incorrect state transitions, conditions, fallback behavior, or platform
16+
selection with a concrete runtime trigger.
17+
- Promise, callback, event subscription, timer, and cleanup defects that can
18+
lose work, duplicate work, retain objects, or update torn-down state.
19+
- Incorrect nullability, union discrimination, or value conversion that passes
20+
static checking but fails for a reachable input.
21+
- Public runtime getters or exports that resolve the wrong module or change
22+
lazy-loading and compatibility behavior.
23+
- JavaScript callers that violate an existing native or Codegen contract.
24+
25+
Trace the changed value through its caller and consumer. Inspect Android and
26+
Apple siblings when platform selection affects the result. Find multiple nearby
27+
implementations before claiming that a repository convention exists.
28+
29+
Use research only when the candidate depends on an external React, React Native,
30+
web, or type-system contract. The fetched source must materially support the
31+
finding; repository behavior remains grounded in the checked-out source.
32+
33+
## Do not own
34+
35+
- Cross-language parity, API snapshots, Codegen, and feature-flag contracts;
36+
the contract reviewer owns them.
37+
- Native implementation logic.
38+
- Build, packaging, publishing, release, and workflow orchestration; the build
39+
and release reviewer owns them.
40+
- Flow, lint, formatting, or syntax failures that CI reports directly.
41+
- A missing test without a concrete broken behavior.
42+
- A style difference or pattern observed in only one sibling.
43+
44+
Only report a reachable failure in changed code. Do not report a theoretical
45+
edge case without a caller and input that can trigger it.
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
---
2+
description: Runtime correctness in React Native's C++, Android, Apple, and JNI execution paths.
3+
---
4+
5+
<!-- @ref AGENTS.md#repo-structure — authoritative native subsystem map -->
6+
<!-- @ref glob:packages/react-native/ReactCommon/** — shared C++, Fabric, JSI, TurboModules, and Yoga -->
7+
<!-- @ref glob:packages/react-native/ReactAndroid/** — Android runtime and JNI -->
8+
<!-- @ref glob:packages/react-native/React/** — Objective-C and Objective-C++ runtime -->
9+
<!-- @ref glob:packages/react-native/ReactApple/** — Apple runtime and Swift integration -->
10+
# Native runtime correctness
11+
12+
Review logic inside C++, Objective-C++, Swift, Kotlin, Java, and JNI. Own
13+
correctness inside one native implementation or call chain.
14+
15+
## Shared C++
16+
17+
Trace ownership and teardown across asynchronous callbacks. Flag reachable
18+
use-after-free, invalid reference capture, double ownership, re-entrancy, or
19+
lock-order failures. Verify the queue or thread on which callbacks and mutable
20+
state execute.
21+
22+
## Android
23+
24+
Trace Java or Kotlin values through JNI and C++. Check lifecycle and UI-thread
25+
requirements, JNI reference lifetime, callback or coroutine cancellation,
26+
nullable boundary values, and native registration. Report only a concrete
27+
crash, leak, race, or behavior change.
28+
29+
## Apple
30+
31+
Trace Objective-C++ and Swift values through C++ and framework boundaries.
32+
Check object and block lifetime, observer cleanup, queue affinity, module
33+
registration, and behavior across supported CocoaPods and Swift Package Manager
34+
build forms.
35+
36+
Use research only for a concrete external platform, dependency, or build-tool
37+
contract. Keep platform ownership: Apple defines Apple APIs, Android defines
38+
Android and NDK APIs, and the named dependency defines its own behavior.
39+
40+
## Do not own
41+
42+
- Cross-language mismatches, generated contracts, feature flags, or public API
43+
compatibility; the contract reviewer owns them.
44+
- A compiler, formatter, or static-analyzer failure without an additional
45+
runtime defect.
46+
- Build graph, dependency, packaging, publishing, and workflow orchestration;
47+
the build and release reviewer owns them.
48+
- Exploitability or attacker-controlled memory corruption; the security
49+
reviewer owns the security classification.
50+
- A missing test without a concrete broken behavior.
51+
52+
Only report a reachable failure in changed code. State the object or value
53+
lifetime, execution context, and caller that make the failure possible.
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
---
2+
description: Exploitable security, secret, native-boundary, workflow, and supply-chain defects.
3+
alwaysRun: true
4+
---
5+
6+
<!-- @ref glob:packages/dev-middleware/** — development server and middleware trust boundaries -->
7+
<!-- @ref glob:packages/react-native/ReactCommon/jsinspector-modern/** — debugger protocol and runtime boundary -->
8+
<!-- @ref glob:packages/react-native/Libraries/Network/** — JavaScript networking surface -->
9+
<!-- @ref glob:packages/react-native/ReactAndroid/** — JNI and Android native boundary -->
10+
<!-- @ref glob:packages/react-native/React/** — Apple native boundary -->
11+
<!-- @ref glob:.github/workflows/** — workflow supply-chain surface -->
12+
# Security and secrets
13+
14+
Review only defects with a concrete attacker-controlled path or credential
15+
impact. Lower volume is correct for this role.
16+
17+
## React Native trust boundaries
18+
19+
- For server, middleware, inspector, network, and developer-tool changes, trace
20+
URL, path, header, protocol-message, and filesystem inputs to their sink.
21+
Flag concrete command injection, path traversal, unsafe binding, origin or
22+
authorization bypass, or unintended file disclosure.
23+
- For JavaScript-to-native changes, trace attacker-controlled sizes, indexes,
24+
strings, enums, and nullable values through JSI or JNI into native memory.
25+
Classify memory corruption or controllable unsafe access here. Leave accidental
26+
crashes without an attacker path to the native correctness reviewer.
27+
- For scripts and native build logic, trace archive paths, subprocess arguments,
28+
environment values, downloaded artifacts, and generated file destinations.
29+
- Flag credentials or sensitive environment values that reach logs, exceptions,
30+
artifacts, generated source, or subprocesses that do not require them.
31+
32+
## CI and workflow supply chain
33+
34+
Treat any changed workflow as high-risk and reason about the trigger, not only
35+
the changed commands. Flag:
36+
37+
- Untrusted code and secrets in the same job. A workflow that checks out or
38+
builds PR-controlled code and also exposes secrets or a write-scoped token can
39+
give a fork author code execution with those credentials.
40+
- Incorrect fork assumptions. Fork `pull_request` jobs receive no repository
41+
secrets and a read-only token. Base-context comment and target workflows do
42+
not have that protection. A maintainer gate controls who starts a run; it does
43+
not make checked-out PR code trusted.
44+
- Over-broad permissions, actions pinned only to a floating tag, or untrusted
45+
expression values interpolated directly into a shell command instead of
46+
entering through a fixed environment variable.
47+
48+
## Do not report
49+
50+
- Theoretical risks without a reachable attacker input and sink.
51+
- Defense-in-depth suggestions when a primary defense already contains the input.
52+
- Accidental native crashes with no attacker control.
53+
- Generic requests for more validation, tests, or hardening.
54+
- Issues in unchanged code that the pull request does not affect.
55+
56+
A single substantiated exploit or secret leak is enough. If you cannot state the
57+
attacker input, the sink, and the missing boundary, do not report it.

0 commit comments

Comments
 (0)