Move inline content that cannot fit beside floats to the first suitable slot,
and retain that clearance in CSS baseline and container-height calculations.
This places GitHub's full-width Show more activity button below its timeline.
Update Taffy to e4e8f77c for float segment extension and content-slot fallback.
Preserve whitespace collapsing around out-of-flow loading hints and cover
float placement, staggered heights, and pre/nowrap behavior in regressions.
Consume child-frame navigation before the Runtime.enable helper clears
collected events, avoiding an event-ordering race in the Fetch test.
Use a local connection-drop server to trigger nested worker script load
failure, removing external DNS timing from the asynchronous error-event test.
Preserve the constructor, event type, message, and filename assertions and
verify that the fixture receives the expected child script request.
Use collision-checked random UUIDs for object URL identifiers instead of a process-local counter. Reuse the existing UUID generation for Blob identity and cover URL format plus independent lifetime for multiple URLs referencing one Blob.
Record XMLHttpRequest response timing through the existing resource entry path for streaming and buffered responses. Cover the request URL, xmlhttprequest initiator type, native PerformanceResourceTiming identity, and exactly one network request.
Snapshot the initiating script nonce when scheduling string timeouts and intervals, then restore it on the compiled timer source. Cover dynamic imports, nested timers, identical source scheduled under different nonces, and functions invoked by another script.
Serve raw XHR header inspection and echo endpoints with exact name/value filters, original ordering and duplicate fields. Reuse arbitrary-method routing and return early without reading unused uploads; cover CORS metadata, HEAD and discovery boundaries.
Serve JSON module load/error dependencies and the per-key JSON-to-JavaScript response sequence. Keep counters shared across fixture origins and isolated between servers, with exact resource discovery and HEAD behavior.
Allow ws sources to match http and https, and wss sources to match https.
Distinguish WebSocket-to-HTTP compatibility from exact scheme matching and
secure upgrades so same-security ports remain constrained and self does not
mistake distinct origins for the same origin.
Cover scheme sources and exact/wildcard hosts with wildcard ports in both
Window and Worker checks, plus numeric ports, host/path restrictions and
asymmetric scheme transitions.
Parse CSP host-source syntax before matching, retaining raw host and path
components instead of normalizing them through the URL parser. Match paths
by percent-decoding individual segments for exact and wildcard sources.
Cover invalid tokens, encoded delimiters, distinct non-UTF-8 bytes, dot
segments, redirect restrictions, ports and hostname boundaries. Preserve
existing support for ordinary IPv4 sources.
(cherry picked from commit 889babcac9)
Split response CSP and report-only fields into independent policies in wire order. Preserve policy disposition and CSP whitespace behavior, and enforce every policy in a field. Preserve source token whitespace after directive splitting so invalid vertical tabs cannot become wildcard permissions.
Source: dcb55392f5, 889babcac9
Exclude partitioned cookies from the unpartitioned global quota and scope
per-domain counting and eviction to the complete partition key. Loading a
Chrome profile with CHIPS cookies now preserves ordinary login cookies
such as V2EX A2.
Add regression coverage for independent global and partition quotas,
partition-local eviction, and replacement at the limit.
Validation: cargo fmt --all and workspace/all-targets/all-features clippy
with -D warnings passed. The three new regressions passed, and a real
Chrome profile retained A2 unchanged and restored the V2EX login.
The full nextest run was stopped at the user's request; an unrelated
non-UTF-8 SQLite filename test failed on this macOS filesystem before
cancellation.
Use the native Window brand to recognize child globals across method realms. Distinguish valid detached child Windows from invalid receivers when adding or removing event listeners; detachment has already cleared their event state.
Cover retained child references, borrowed EventTarget methods, invalid receivers, and parent listener isolation. Restore the verified iframe promise-rejection WPT to the passed list.
Return text mutation effects from parser sinks and deliver them through the shared notification pipeline after releasing the structural borrow. This keeps stylesheets and layout current when parser input is merged into existing text nodes, and delivers characterData records without replacing node identity.
Add main-document and iframe regressions for split stylesheet input, hit testing, and MutationObserver delivery. Restore the verified elementsFromPoint iframe WPT to the passed list.
Record the full 12,905-case run at 4f7c4ffc0: 8,766 passed, 3,792 failed, 285 timed out, 53 stalled, and 9 errors. Preserve the measured full-run classifications, including the two independently confirmed stable regressions.
Serve the upstream CORS echo endpoint for standard and custom methods, including original query/body metadata, repeated allow-headers fields, delay errors, HEAD, and exact resource discovery.
Source: 9b27c82fb5