Keep request origin independent of URL resolution and referrer context,
including local blob fetches and inherited or sandboxed srcdoc documents.
Reject missing browser origins at the resource client boundary and retain
one Request across Service Worker redirects and network fallback.
Cover dispatch rejection, wire Origin/Cookie headers, memory-cache
partitioning and preserved Service Worker request metadata.
Validation: workspace fmt and Clippy passed; Nextest passed 17,517 tests
with 13 existing skips. Renderer test debug symbols were disabled to fit
available build memory; tests and debug assertions were unchanged.
Name coalesced work by the native caches it invalidates, and document that the Worker armed bit tracks the outstanding fallback message rather than mailbox contents.
Consolidate Date/Intl options regressions into named cases and fold time-first legacy dates into the shared parsing matrix, retaining their inputs and native-semantic assertions.
Publish typed invalidation flags under the environment lock and wake isolate owners only after releasing it. Bound page and worker notification work while preserving command FIFO, teardown safety, and observation ordering.
Remove stale wrapper-era dependencies and terminology, and add mailbox race and CDP burst regressions.
Generate Origin independently of browser destination metadata, and attach script
metadata at classic, module, and preload request builders. Share redirect URL-list
rules across request generation and response validation, and remove final-only
CORS validation from manifests, stylesheets, and request interception.
Reject failed CORS checks even without supported integrity metadata. Preserve CSP
reporting before dynamic script fetches and use committed Window origins for
srcdoc and sandboxed child script/module requests.
Add wire-level Origin, Cookie, and Fetch Metadata regressions, plus manifest,
stylesheet CSSOM, CSP, and child module/preload coverage.
Keep redirect history in Request so Service Worker handoffs, network
redirects, preflights, Origin serialization, cookies, and TLS credentials
share the same state. Avoid reusing another request's response URL list
from the renderer memory cache.
Validate and filter network responses using their full history while
preserving readable Service Worker response filters across streaming and
buffered delivery. Returning to the initiating origin keeps network CORS
tainting; worker-produced responses retain their own filtering.
Add wire-header, credentials, cache, and worker response regressions, and
correct the local Fetch/XHR redirect fixtures to authorize and expose CORS
responses after a cross-origin round trip.
Distinguish network, service worker, and browser-internal redirects so synthetic responses are not subjected to network CORS checks. Preserve every hop for redirect taint and Origin validation, including across navigation response conversions.
Add seven cross-origin service worker script scenarios and guard CORS checks for cached network redirects without ExtraInfo. The new integration regression fails before the fix and passes afterward.
Validated with cargo fmt --all, workspace Clippy across all targets and features with warnings denied, and cargo nextest run --no-fail-fast: 17459 passed, 13 skipped. Used one build job for the full test run after a parallel-build rustc process was killed.
Refresh the all profile on 59e1af954 against WPT db95fafd1 using CDP, 50 workers, and an 800x600 viewport at DPR 1.
Record all 12,668 cases: 8,558 pass, 3,760 fail, 284 timeout, 52 harness-stalled, and 14 error; no crashes or missing cases. Compared with the previous lists, 36 cases became passing and 8 became non-passing.
Preserve the full-run observations. In two focused runs at parallelism 8 and one serial run, seven of the eight previously passing cases passed each time. The CSP javascript URL inheritance case failed all three rechecks because the expected report was absent; its underlying cause remains undiagnosed.
Preserve response filtering through script and service worker loading, validate CORS authorization across redirects, and reject opaque responses before computing supported integrity digests. Keep empty and unsupported metadata behavior unchanged.
Add parser, dynamic script, module, and service worker regressions covering 39 scenarios. Validated with cargo fmt --all, full workspace Clippy, and cargo nextest run --no-fail-fast (17457 passed, 13 skipped).
Make process environment owners non-cloneable RAII authorities, share session admission while preserving failed and no-op outcomes, and consolidate duplicate isolate-entry handling. Keep read-only owner queries side-effect-free and add lifecycle regressions.
Remove the Date/Intl wrappers, custom date parser and per-Page replay state. Keep exclusive locale/timezone ownership in a process controller and refresh existing Page and Worker isolates through generation-bound notifications and observation boundaries, including nested Inspector pauses.
Release claims on session/target/context retirement, retain native coercion and locale matching, and cover lifecycle restoration with Rust, BiDi and process-isolated CDP regressions.
Handle Unicode and legacy date inputs without unsafe slicing or timezone corruption. Normalize ICU locale IDs with the bundled ICU library and forward Intl options without violating frozen-object invariants. Add renderer regressions and process-isolated CDP input coverage.
Move Fontconfig matching, substitution policy, and the Fontique lookup cache into moli-system-fonts. Keep CSS family adaptation in moli-layout, migrate tests and fixtures, and retain the Skia notice in source comments.
Refresh the all profile on a33217690 against WPT db95fafd1, using CDP,
50 workers, and an 800x600 viewport at DPR 1.
Record all 12,668 cases: 8,530 pass, 3,783 fail, 295 timeout,
50 harness-stalled, and 10 error; no crashes or missing cases.
Include fetch/api/abort/destroyed-context.html and resolve three iframe
cases previously listed under both pass and error. Preserve the full-run
observations, including 16 cases that changed from pass to fail.
Include queued HTTP work in the owner's runnable decision after completions release active slots. Share the global and per-origin eligibility checks with the startup path so blocked queues still allow the owner to wait.
Add native owner regressions that consume submission wakeups before releasing a held request, then require the queued request to finish within its short deadline. Cover both scheduler limits and priority queues whose head is blocked by an origin cap.