Publish realm-owned interface objects only after finalization succeeds and route shared binding helpers through the canonical registry. Keep ECMAScript intrinsics separate and check native realm exposure when deserializing CryptoKey objects.
Validate the main WindowProxy and script environment while the source stays
live, and preallocate the replacement bootstrap state. Move the guarded
entry to Committed before consuming its one-shot detachment token so a
panic cannot return a detached source through live failure handling.
Keep source retirement inside CommittedNavigationEntry, rename the
phase-one retirement entry points, and retire the lifecycle turn once.
Check replacement liveliness before consuming the committed residence.
Cover panics immediately after detachment and during source retirement for
ordinary and open-streaming Pages, including receiver release and renderer
owner reuse after the failed navigation.
Keep the complete source phase-one residence and context resources intact
until navigation commit validation and WindowProxy detachment succeed.
Retire the parser, input bridge and ScriptVm synchronously after that
boundary, and defer source lifecycle termination until commit.
Cover replacement success, 204 No Content, and script-environment and
WindowProxy ownership failures after a replacement response is Prepared.
Verify failed commits preserve the source Inspector context, later body
bytes still parse, and the original Document reaches Load.
Create Streams promise residences with V8 PromiseResolver so writer
ready/closed promises and pending operations do not consult a missing,
throwing or replaced public Promise constructor during bootstrap.
Consume the private resolver on first settlement to preserve
[[AlreadyResolved]] while adopting a still-pending promise. Keep delayed
read rejections on the same settlement path.
Cover allocation before interface bootstrap and writer backpressure and
releaseLock with deleted, undefined or poisoned global Promise bindings.
Start iframe-input with --scrollbars so its nested native control checks
continue to exercise visible scrollbars. Add a default scrollbar-visibility
group covering fetch/serve defaults, boolean environment values and CLI
precedence, geometry, stable gutters, frames, PNG output and input routing.
Cover CDP toggling, navigation, target isolation, detach, resize and layout
dependencies in independent processes with explicit environments.
Validation: 43 harness unit tests passed; scrollbar-visibility (22 scenarios),
iframe-input and classic-scrollbar smoke groups all passed (3/3).
Apply scrollbar hiding to the live Page before acknowledging the command, preserve the startup flag, and replay the target setting before navigation scripts. Validate the required boolean and layout mode, track per-session state, and clear overrides on detach.
Refs #1081
Hide native scrollbars and automatic gutters while preserving scrolling and explicit stable gutters. Require layout mode and retain the setting across navigation, frames, and protocol sessions.
Refs #1081
Exercise Range requests through buffered, HTML and raw transports, including malformed or empty Range values, native header configuration and redirects. Inspect wire headers to ensure identity encoding is selected for Range without leaking into subsequent ordinary requests, while response decompression remains active.
Run the 451451cec release against WPT db95fafd1f with the full all profile,
CDP mode, and 50 workers. Record all 13,631 executed cases: 9,583 passed,
3,724 failed, 259 timed out, 10 errored, 1 crashed, and 54 stalled.
Both Promise and both Wasm entry-settings regressions now pass in the full
run and in all five focused release rounds. Keep the other original full-run
statuses, including errors and intermittent failures; diagnostic comparisons
with main and the previous release do not replace snapshot results.
Audit confirms every raw result agrees with the engine report, matrix, and
eight sorted, disjoint status lists, with no missing or unexecuted cases.
A popup-scoped identity lookup can miss a load callback created in its
parent or another live iframe. The retirement guard then rejects the
callback solely because its context has a Window token, causing the
Promise and Wasm entry-settings WPTs to time out.
Resolve the callback creation context's concrete registration when no
scoped identity was provided, then apply the existing currentness check.
Unregistered Window realms remain retired and captured identities retain
their original authority.
Add a Page-task regression that opens a popup through an iframe and checks
parent and live-child callbacks, their receivers and event targets. A
callback retained from a removed/reinserted iframe Window must not run.
Validation: cargo fmt --all; workspace/all-targets/all-features Clippy with
-D warnings; cargo nextest run --no-fail-fast with retries disabled
(19,166 passed, 16 skipped). The new regression passes 20 stress iterations;
the 60 popup and callback-retirement tests pass all three stress rounds.