Select Accept-Encoding: identity when a Range header is present, while preserving explicit embedder encoding preferences. Exercise buffered, HTML and raw transports, malformed and empty ranges, redirects, repeated requests and response decompression.
Preserve the full error chain in network failure reasons and the CLI fallback so curl error codes and detailed TLS, DNS, and connection failures remain visible. Keep the concise two-line CLI presentation and typed readiness timeout handling.
Test TLS failures across all fetch transports, network error classifications, and CLI connection failures. Validated with cargo fmt --all, workspace Clippy with all targets and features, and cargo nextest run --no-fail-fast (18444 passed).
Refs #701
Carry raw response header values through fetch, caches, redirects,
renderer delivery, workers, and protocol records. Convert explicitly
at WebIDL and protocol text boundaries while preserving opaque bytes.
Keep legacy CacheStorage and service worker metadata readable, and
advance the HTTP cache format for raw header values.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast
Keep duplicate header entries in storage and copy inherited Request headers from private state. Apply sort-and-combine only at the relevant consumer boundaries, while explicit HeadersInit values retain WebIDL iterable conversion.
Run no-cors cases through real Window and Worker fetch transports, preserve empty fields on the wire, and correct the local Request getter propagation fixture.
Restore original headers on redirect while preserving current-hop overrides
for authentication retries and keeping Network event identity intact.
Preserve raw BiDi Cookie, Set-Cookie, and extra header values through page,
navigation, and worker policies. Apply CDP's last-value behavior for duplicate
request header names.
Add coverage for header bytes, redirects, authentication, and event sequences.
Carry RequestHeaders through navigation, Fetch/XHR, workers, redirects and auth,
with explicit Unicode and ByteString conversions at protocol and WebIDL boundaries.
Share the raw curl header list with WebSocket transport and decode binary response
headers without UTF-8 replacement. Keep header memory charging concrete.
Cover opaque values, UTF-8 overrides, duplicates, redirect/auth continuation and
WebSocket handshakes with byte-level regression tests.
Extracted from b57d75e801791c4d9b6d682f2aae254d3acd3c53.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings. Runtime tests were not run for this split.
Extracted from f25578c2a9c188d3437e88f337ebaae9da49a246.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings. Runtime tests were not run for this split.
Configure an empty upload for a bodyless PUT and suppress libcurl’s implicit Content-Type on that path. Recompute framing across redirects, retaining PUT for 301/302/307/308 and dropping the body headers when 303 changes it to GET.
Source: f84c99d671
Use byte-only decomposition for Response and NavigationResponse instead of
discarding the text returned by into_parts(). Module, dedicated worker, and
service worker consumers now transfer the existing exact byte allocation.
Verify storage transfer for UTF-8 and non-UTF-8 payloads.
Source: e32030e484
Keep request origin independent of URL resolution and referrer context,
including local blob fetches and inherited or sandboxed srcdoc documents.
Reject missing browser origins at the resource client boundary and retain
one Request across Service Worker redirects and network fallback.
Cover dispatch rejection, wire Origin/Cookie headers, memory-cache
partitioning and preserved Service Worker request metadata.
Validation: workspace fmt and Clippy passed; Nextest passed 17,517 tests
with 13 existing skips. Renderer test debug symbols were disabled to fit
available build memory; tests and debug assertions were unchanged.
Generate Origin independently of browser destination metadata, and attach script
metadata at classic, module, and preload request builders. Share redirect URL-list
rules across request generation and response validation, and remove final-only
CORS validation from manifests, stylesheets, and request interception.
Reject failed CORS checks even without supported integrity metadata. Preserve CSP
reporting before dynamic script fetches and use committed Window origins for
srcdoc and sandboxed child script/module requests.
Add wire-level Origin, Cookie, and Fetch Metadata regressions, plus manifest,
stylesheet CSSOM, CSP, and child module/preload coverage.
Keep redirect history in Request so Service Worker handoffs, network
redirects, preflights, Origin serialization, cookies, and TLS credentials
share the same state. Avoid reusing another request's response URL list
from the renderer memory cache.
Validate and filter network responses using their full history while
preserving readable Service Worker response filters across streaming and
buffered delivery. Returning to the initiating origin keeps network CORS
tainting; worker-produced responses retain their own filtering.
Add wire-header, credentials, cache, and worker response regressions, and
correct the local Fetch/XHR redirect fixtures to authorize and expose CORS
responses after a cross-origin round trip.
Distinguish network, service worker, and browser-internal redirects so synthetic responses are not subjected to network CORS checks. Preserve every hop for redirect taint and Origin validation, including across navigation response conversions.
Add seven cross-origin service worker script scenarios and guard CORS checks for cached network redirects without ExtraInfo. The new integration regression fails before the fix and passes afterward.
Validated with cargo fmt --all, workspace Clippy across all targets and features with warnings denied, and cargo nextest run --no-fail-fast: 17459 passed, 13 skipped. Used one build job for the full test run after a parallel-build rustc process was killed.
Remove the separate WebSocket CURLSH connection cache so HTTP/1, HTTP/2 and WebSocket sockets compete for the existing host and total limits. Retain bounded session admission and message memory limits.
Pin the curl fork's connect-only eviction fix so quiet upgraded sockets remain owned until their connections close. Cover queueing, deadlines, cancellation, shutdown and HTTP/2 multiplexing under a full shared connection budget.