Skip to content

fix(cli): expose benign globals in run-code vm context - #42975

Merged
Pavel Feldman (pavelfeldman) merged 1 commit into
microsoft:mainfrom
pavelfeldman:fix-cli-471
Sep 28, 2026
Merged

Pavel Feldman (pavelfeldman) merged 1 commit into
microsoft:mainfrom
pavelfeldman:fix-cli-471

Conversation

@pavelfeldman

Copy link
Copy Markdown
Member

Summary

  • Expose timers, fetch, URL, Buffer, crypto, AbortController, TextEncoder/TextDecoder and similar globals in the run-code vm context; require and process stay unavailable.
  • Document the available globals in the running-code.md skill reference.

Fixes microsoft/playwright-cli#471

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

2 failed
❌ [chromium] › mcp/webmcp-dynamic.spec.ts:189 › a tool registered in an iframe can be called after the page is reloaded @mcp-macos-latest-chromium
❌ [firefox] › mcp/annotate.spec.ts:446 › should switch screencast to -s session on show --annotate @mcp-windows-latest-firefox

8827 passed, 1480 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Hi, I'm the Playwright bot and I took a first look at the MCP failures here.

🟢 Both failures look like pre-existing flakes

Both tests have failed with the same assertion on main and on other PRs. Neither test goes through the run-code VM context this PR changes.

Details

This PR only changes browser_run_code_unsafe / run-code: it adds timers, URL, fetch, Buffer and other globals to the vm context in tools/backend/runCode.ts. It also updates the docs and the run-code specs. Neither failing test uses that tool. I checked against the test-results DB snapshot. The incremental update step hit a GitHub API 500, so this PR's own runs aren't in it.

Pre-existing flake / infra

Triaged by the Playwright bot - agent run

@pavelfeldman
Pavel Feldman (pavelfeldman) merged commit e8149b8 into microsoft:main Sep 28, 2026
16 of 18 checks passed
Yury Semikhatsky (yury-s) added a commit to microsoft/playwright-cli that referenced this pull request Sep 28, 2026
## Fixes

- `run-code` scripts can use timers, `fetch`, `URL`, `Buffer`, `crypto`,
`AbortController` and `TextEncoder`/`TextDecoder`; `require` and
`process` stay unavailable
([#471](#471)).
([microsoft/playwright#42975](microsoft/playwright#42975))
- `find --filename=results.md` saves matches to a file when a query
produces too many of them
([microsoft/playwright#42077](microsoft/playwright#42077)).
([microsoft/playwright#42968](microsoft/playwright#42968))
- `goto` and `reload` report a dialog opened during page load instead of
timing out
([microsoft/playwright#42817](microsoft/playwright#42817)).
([microsoft/playwright#42908](microsoft/playwright#42908))
- The session no longer crashes when the browser is closed during a
download
([microsoft/playwright#42831](microsoft/playwright#42831)).
([microsoft/playwright#42922](microsoft/playwright#42922))
- `install-browser --no-shell` is accepted instead of failing with
`Unknown option: --shell`
([microsoft/playwright#42804](microsoft/playwright#42804)).
([microsoft/playwright#42871](microsoft/playwright#42871))
- `webmcp-call` no longer runs a tool in a stale tab or frame
([microsoft/playwright#42816](microsoft/playwright#42816)).
([microsoft/playwright#42821](microsoft/playwright#42821))
- `webmcp-call` works with Chromium 155+.
([microsoft/playwright#42915](microsoft/playwright#42915))
- Snapshots quote accessible names that look like regexes, e.g.
`"/home/"`
([microsoft/playwright#42807](microsoft/playwright#42807)).
([microsoft/playwright#42811](microsoft/playwright#42811))
- The bundled skill only preapproves Playwright commands instead of any
`npm` and `npx` command
([microsoft/playwright#42745](microsoft/playwright#42745)).
([microsoft/playwright#42789](microsoft/playwright#42789))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

request-mocking.md "Delayed Response" example uses setTimeout, which run-code doesn't provide

2 participants