Skip to content

Support injecting scriptlets in one shared scope - #64

Merged
chrmod merged 3 commits into
mainfrom
shared-scope-injection
Oct 6, 2026
Merged

chrmod merged 3 commits into
mainfrom
shared-scope-injection

Conversation

@chrmod

@chrmod chrmod commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Each scriptlet func inlined its own safeSelf(), so stacked hooks compounded (2^n). #63 shared the cache through a Symbol.for property on globalThis, which pages can enumerate and use to reach the unhooked natives.

uBO avoids this by running all scriptlets of a frame in one scope with each dependency declared once. This replaces the per-scriptlet func wrappers and the global with:

  • an index of scriptlets with aliases, world, requiresTrust and fn
  • run(scriptletGlobals, calls): one function that declares every uBO function once and calls the requested scriptlets; the extension passes it to chrome.scripting.executeScript and serializes it for registered scripts

Bundle goes from 2.2 MB to 0.24 MB.

@chrmod
chrmod requested a review from philipp-classen October 6, 2026 12:01
@chrmod
chrmod marked this pull request as ready for review October 6, 2026 12:01
@chrmod
chrmod merged commit 9f09b9f into main Oct 6, 2026
2 checks passed
@chrmod
chrmod deleted the shared-scope-injection branch October 6, 2026 14:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants