Validate the main WindowProxy and script environment while the source stays
live, and preallocate the replacement bootstrap state. Move the guarded
entry to Committed before consuming its one-shot detachment token so a
panic cannot return a detached source through live failure handling.
Keep source retirement inside CommittedNavigationEntry, rename the
phase-one retirement entry points, and retire the lifecycle turn once.
Check replacement liveliness before consuming the committed residence.
Cover panics immediately after detachment and during source retirement for
ordinary and open-streaming Pages, including receiver release and renderer
owner reuse after the failed navigation.
Keep the complete source phase-one residence and context resources intact
until navigation commit validation and WindowProxy detachment succeed.
Retire the parser, input bridge and ScriptVm synchronously after that
boundary, and defer source lifecycle termination until commit.
Cover replacement success, 204 No Content, and script-environment and
WindowProxy ownership failures after a replacement response is Prepared.
Verify failed commits preserve the source Inspector context, later body
bytes still parse, and the original Document reaches Load.
Create Streams promise residences with V8 PromiseResolver so writer
ready/closed promises and pending operations do not consult a missing,
throwing or replaced public Promise constructor during bootstrap.
Consume the private resolver on first settlement to preserve
[[AlreadyResolved]] while adopting a still-pending promise. Keep delayed
read rejections on the same settlement path.
Cover allocation before interface bootstrap and writer backpressure and
releaseLock with deleted, undefined or poisoned global Promise bindings.
Start iframe-input with --scrollbars so its nested native control checks
continue to exercise visible scrollbars. Add a default scrollbar-visibility
group covering fetch/serve defaults, boolean environment values and CLI
precedence, geometry, stable gutters, frames, PNG output and input routing.
Cover CDP toggling, navigation, target isolation, detach, resize and layout
dependencies in independent processes with explicit environments.
Validation: 43 harness unit tests passed; scrollbar-visibility (22 scenarios),
iframe-input and classic-scrollbar smoke groups all passed (3/3).
Apply scrollbar hiding to the live Page before acknowledging the command, preserve the startup flag, and replay the target setting before navigation scripts. Validate the required boolean and layout mode, track per-session state, and clear overrides on detach.
Refs #1081
Hide native scrollbars and automatic gutters while preserving scrolling and explicit stable gutters. Require layout mode and retain the setting across navigation, frames, and protocol sessions.
Refs #1081
Exercise Range requests through buffered, HTML and raw transports, including malformed or empty Range values, native header configuration and redirects. Inspect wire headers to ensure identity encoding is selected for Range without leaking into subsequent ordinary requests, while response decompression remains active.
Run the 451451cec release against WPT db95fafd1f with the full all profile,
CDP mode, and 50 workers. Record all 13,631 executed cases: 9,583 passed,
3,724 failed, 259 timed out, 10 errored, 1 crashed, and 54 stalled.
Both Promise and both Wasm entry-settings regressions now pass in the full
run and in all five focused release rounds. Keep the other original full-run
statuses, including errors and intermittent failures; diagnostic comparisons
with main and the previous release do not replace snapshot results.
Audit confirms every raw result agrees with the engine report, matrix, and
eight sorted, disjoint status lists, with no missing or unexecuted cases.
A popup-scoped identity lookup can miss a load callback created in its
parent or another live iframe. The retirement guard then rejects the
callback solely because its context has a Window token, causing the
Promise and Wasm entry-settings WPTs to time out.
Resolve the callback creation context's concrete registration when no
scoped identity was provided, then apply the existing currentness check.
Unregistered Window realms remain retired and captured identities retain
their original authority.
Add a Page-task regression that opens a popup through an iframe and checks
parent and live-child callbacks, their receivers and event targets. A
callback retained from a removed/reinserted iframe Window must not run.
Validation: cargo fmt --all; workspace/all-targets/all-features Clippy with
-D warnings; cargo nextest run --no-fail-fast with retries disabled
(19,166 passed, 16 skipped). The new regression passes 20 stress iterations;
the 60 popup and callback-retirement tests pass all three stress rounds.
Run the unfiltered all profile with release Moli 1.1.12 built from
0c5f83969f after rebasing onto main
8f7598a30f, using WPT
db95fafd1fcef8428805e41eb5705d444e8c67ce and 50 CDP workers.
Complete all 13,631 cases: 9,578 pass, 3,730 fail, 261 timeout, 9 error,
one crash and 52 harness-stalled. Against main's lists, 11 cases gain pass
and 16 lose pass, for a net decrease of five. Preserve the raw full-run
outcomes.
Validate the unchanged case set and exactly one recorded result per case.
Raw live results, engine output, matrix and all eight sorted, disjoint,
exhaustive status lists agree. No setup errors, missing cases, unknown
statuses or unexecuted recovery placeholders. git diff --check passes.
Check all 16 pass losses against the same release main source and WPT.
Four Promise/Wasm entry tests reproduce a source regression: HEAD times
out in 8/8 paired trials while main passes 8/8. The callback retirement
guard added in 77d2700c6 is the cause; a diagnostic-only fallback restores
all four in 3/3 trials. Keep these failures in the raw timeout list.
Nine losses also fail on main; two original failures remain unreproduced.
rel-attribute-clearing remains suspicious (HEAD 3/28 failures, main 0/28).
Filtered validation does not alter this full-run snapshot.
Keep the private Document wrapper slot and Window.document getter together in
the Window binding layer. Bind environment settings and the wrapper through
one guarded entry point, leaving WindowEnvironmentSettings responsible for
native document identity, origin and base URL resolution.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets --all-features
-- -D warnings; cargo nextest run --no-fail-fast.
Resolve Window.document through the receiver realm's retained settings and
keep its original Document wrapper in a private V8 slot after cache retirement.
Use the same getter for the LegacyUnforgeable bootstrap descriptor.
Cover cleanup, reinsertion, borrowed getters and navigation, including retained
Request regressions for about:blank, srcdoc and HTTP frames.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets --all-features
-- -D warnings; cargo nextest run --no-fail-fast (19,146 passed, 16 skipped).