Normalize header values after WebIDL conversion and state checks, reject
invalid names or values with SyntaxError, and ignore forbidden request
headers. Combine repeated values with comma-space while retaining the
first name and empty list members.
Keep quoted strings intact in the shared method-override filter so quoted
commas do not turn permitted values into forbidden methods. Cover error
ordering, reentrant argument conversion, and actual outgoing headers.
Validation: cargo fmt --all, workspace all-targets/all-features Clippy with
-D warnings, and cargo nextest run --no-fail-fast pass (17973 passed,
13 skipped). The 37-case WPT check improves from 22 to 27 passing cases and
300 to 388 passing assertions, without regressions. All 20 supplemental
Window/Worker checks pass across synchronous and asynchronous XHR.
Implement xhr/resources/inspect-headers.py with raw header names, duplicate
values, byte-preserving filters, and its upstream CORS response headers.
Support HEAD, uploads, and custom methods through the shared XHR dispatch,
and recognize the supported fixture references during case selection.
Validation: all 516 benchmark unit tests pass. 84 HTTP comparisons match
the unmodified upstream handler. With the same Moli binary, 31 WPT cases
improve from 9 to 18 passes and from 80 to 114 passing subtests, without
regressions.
Implement requri.py and redirect.py with their upstream query, status,
Location, delay, and method behavior. Preserve raw request URIs and allow
redirect responses before the upload completes.
Recognize supported XHR references during case selection and cover the
fixtures through real HTTP requests.
Validation: all 510 benchmark unit tests pass. With the unchanged Moli
binary, 17 WPT cases improve from 6 to 9 passes and 72 to 79 passing
subtests; both redirected Worker harnesses now execute their assertions.
Resolve Blob URL bytes and text using the serialized URL without its
fragment. Keep query strings, appended paths, and percent-encoded hash
characters in the lookup key, and preserve exact-match revocation.
Cover fragment lookup, non-fragment suffix rejection, and reference release
after revoking the original URL.
Serialize Response.url and XMLHttpRequest.responseURL without fragments
at the getter boundary. Keep stored response URLs and Request.url intact,
including query strings and percent-encoded hash characters.
Cover Fetch clones and asynchronous/synchronous XHR for local responses.
Use a fresh random UUID for each object URL, as required by File API,
instead of a decimal counter. Reuse the existing UUID generator and check
for collisions while holding the URL map lock.
Extend the lifetime regression to cover independently revoking two URLs
created from the same Blob.
Realm tokens are allocated per JsContextHost while the BlobStore is shared.
Match both resource owner and realm token when retiring ordinary or isolated
window contexts, including failed bootstrap cleanup.
Extend the store and renderer regressions for colliding lifetime identifiers
across two owners and two live VMs.
An opaque response resolves at headers, before its hidden body finishes.
Use the existing pending-subresource drain helper before collecting completed
network records so the assertion does not race the transport terminal.
Reading contentWindow on an iframe in a windowless document must not make
its synthetic child document visible. Determine browsing-context ownership
from native top-level, child frame, and popup registrations, preserving
the document's retained visibility state separately from defaultView.
Cover both getter access orders, nested synthetic frames, and cross-realm
visibility/defaultView getters on live documents and popups.
Follow-up to #501.
Resolve no-cors Fetch responses at their headers in Window and worker realms, preserving header policy checks and cancellation. Keep suspect opaque bytes in capture storage until the existing ORB classifier approves them, including clone, CacheStorage and service-worker consumers.
Verify unfinished streams and real connection closure across Window, child Window and worker realms. All workspace gates pass; 83 related WPT cases gain two abort subtests without regressions.
Preserve the selected request body stream in Window and Worker fetch
bindings. Reject with the original abort reason before synchronously
canceling a readable upload, and handle the internal cancellation promise
without replacing the fetch rejection or reading public Promise methods.
Merge RequestInit bodies and inherited methods before validating the
effective request. Nullish body overrides inherit the input body; invalid
stream options and GET/HEAD bodies fail construction before cancellation.
Remove the obsolete public then shim and its classified direct-call entry.
Add regression coverage for cancellation timing, reason identity, source
errors, body selection, reentry, validation and modified public intrinsics
in Window, iframe and Worker contexts.
Validation: fmt and strict workspace Clippy passed; nextest passed 17,962
tests with 13 skipped. All 12 pre-abort and 3 ordinary-upload CLI probe
groups passed. The 83-case WPT selection gains two passing subtests with
no regressions or new failures; whole-case counts remain 77 pass / 6 fail.
Allocate Body.arrayBuffer() and Body.bytes() results in the receiver's
creation context for buffered, author-stream and pending network bodies.
Retain that context across asynchronous completion and recognize readable
bodies by their internal brand when methods are borrowed across realms.
Add Request/Response regression coverage for both iframe borrowing
directions, null bodies, byte contents, asynchronous and cloned streams,
prototype changes, network rewrapping, and original stream error identity.
Validation: cargo fmt --all; strict workspace Clippy; nextest (17,958
passed, 13 skipped). The 81-case WPT selection improves from 73 to 75
passing cases with no regressions or new failed subtests. All four CLI
regression groups pass (176 checks).
Read and copy Uint8Array chunks through native chunk, close, and error
steps, then materialize using the shared body conversions. Defer internal
streaming callbacks until response registration and network delivery finish.
Remove the JavaScript bootstrap consumer and intrinsic reader plumbing.
Cover inherited then handlers, chunk mutation and detachment, exceptions,
and constructor tampering in window, iframe, and worker contexts.
Model trickle.py by draining the request body, delaying headers and body
chunks, and writing TEST_TRICKLE lines according to ms/count. Preserve the
optional Content-Type omission and close-delimited response framing.
Exercise supported methods, defaults, duplicate/invalid parameters,
progressive delivery, and both fixed-length and chunked uploads.
Validation: 221 Python tests passed. With the same Moli binary, 16 WPT
cases add two passing cases and eight passing subtests, with no regressions.
No Rust source or build metadata changed.
Decode buffered and fetched text/json bodies with UTF-8 BOM removal before
creating strings or invoking the native JSON parser. Remove exactly one
initial BOM, retain replacement behavior for malformed UTF-8, and keep
binary/form consumers unchanged. Borrow valid UTF-8 while materializing.
Cover constructed Request/Response bodies, delayed ReadableStream input,
data URLs, and chunked HTTP in window, child frame, and worker realms.
Include split/repeated BOMs, UTF-16 markers and MIME charset, SyntaxError,
clone ordering, raw bytes, and URL-encoded/multipart form values.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,946 passed, 13 skipped); 9/9 CLI probes. A 40-case WPT comparison adds
four passing cases and ten passing subtests without regressions.
Retain ReadableStream BodyInit values instead of extracting empty bytes.
Validate stream construction options, tee cloned bodies with independent
chunks, and proxy inherited stream-only bodies while immediately marking
the original disturbed. Use native stream operations for cancellation and
error propagation even when public stream methods are overridden.
Cover consumption, clone isolation, validation, errors, and cancellation in
window, child-frame, and worker realms. The 37-case Fetch WPT comparison
adds four passing cases and six passing subtests without regressions;
public stream tee still passes all 52 subtests.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,943 passed, 13 skipped); 9/9 CLI regression probes.
Carry request methods through buffered, streaming, Worker, and navigation
preload response creation. Discard public and filtered internal bodies before
registering streams, so null bodies remain reusable through reads, clones,
and aborts while empty GET responses keep their streams.
Cover real HTTP responses in Window, iframe, and Worker and verify pending
body sources do not retain late chunks or terminal events.
Validation: cargo fmt --all; workspace Clippy with all targets/features and
-D warnings; nextest 17,940 passed, 13 skipped. Focused WPT comparison gained
2 complete cases and 20 subtests across 69 cases with no new failures.
Use byte-only decomposition for Response and NavigationResponse instead of
discarding the text returned by into_parts(). Module, dedicated worker, and
service worker consumers now transfer the existing exact byte allocation.
Verify storage transfer for UTF-8 and non-UTF-8 payloads.
Derive Body usability and bodyUsed from native stream state, preserve reader locks during consumption, and keep null bodies reusable. Reject unusable stream inputs and propagate body conversion failures through their promises.
Use native reader operations without forcing lazy Streams interfaces during bootstrap. Cover buffered and streaming bodies in Window, iframe, and Worker; update null-body expectations and WPT pass lists.
Worker abort events now use the signal realm's intrinsic Event constructor
and carry the native trust flag, including timeout and stream cancellation.
Share AbortSignal dispatch setup and cleanup between Window and Worker.
Script dispatch validates Event state and clears trust, active redispatch
throws, and completion clears currentTarget, eventPhase, the event path,
and propagation flags. Pre-stopped events skip listeners and remain reusable.
Cover controller, composite, stream and timeout events with overwritten or
missing public constructors, plus synthetic dispatch and native event reuse,
in Window, child frames and dedicated workers.
Flatten composite signals to their ordered original sources in Window and
Worker stores. Mark every dependent aborted with the first reason before
running abort algorithms or listeners, then dispatch in dependency order.
Snapshot listeners when each event starts and remove signal-bound DOM
listeners before its abort event. Cover nested and overlapping sources,
reentrant cancellation, empty composites, reason identity, and listener
changes in Window, child frames, and dedicated workers.
Use intrinsic constructors in the Navigation or history entry target realm
for navigate, currententrychange, navigatesuccess, navigateerror and dispose.
Create history entries in their owning window even when methods are borrowed
from another window. Preserve native navigate event trust and construct
navigation abort controllers and trusted abort events through intrinsics.
Add three Browser integration tests covering 14 cross-window, joint-history
and cross-document flows, including throwing public constructor getters.
The same fixture matches Chrome in all 14 flows.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17918 passed, 13 skipped). The 334-case WPT comparison gains two passing
cases and two subtests without regressions; passed ledger is 9107.
Use the active child Document's native complete-load state when choosing
whether iframe src navigation replaces the current history entry. This
covers parser, DOMContentLoaded, load and pageshow callbacks despite an
already complete readyState, while retaining post-load push behavior.
Add Browser coverage for 14 src assignment and setAttribute flows. Update
two existing history expectations for src changes from iframe load
callbacks, independently confirmed with their HTML fixtures in Chrome.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17915 passed, 13 skipped). The 222-case WPT comparison gains three passing
cases and three subtests without regressions; passed ledger is 9105.
Run cross-document child traversal through the shared unload tree after
its root navigation checks, retaining visibility transitions and one
unload lifecycle per retiring document and descendant.
Apply native Window lifecycle events' legacy Document target override
explicitly, and reset trust for script-dispatched events. Add Browser
coverage for native versus synthetic dispatch, nested history/navigation
roundtrips, and same-document traversal.
Validation: cargo fmt --all; workspace Clippy with all targets/features
and -D warnings; nextest (17913 passed, 13 skipped). 213 WPT cases gained
one passing case and two passing subtests with no regressions. Seven
matching Chrome fixture flows passed.
Snapshot retiring frame documents and finish their beforeunload phase before
actual unload delivery. Preserve ancestor unload counters through descendant
callbacks and check exact owners before dispatching further events.
Retain visibility state on the native Document and dispatch trusted, bubbling
visibilitychange events through the host event path. Use native unload
counters to suppress navigation during visibility and ancestor callbacks;
cancel each retiring window's timers after its unload.
Eight Browser integration tests cover 50 scenarios. The 181-case WPT
comparison gains two passing cases and seven passing subtests without
regressions; update the passed ledger to 9,101 cases.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,910 passed, 13 skipped). Rebuilt CLI matches the tested WPT binary.
Keep a native counter for each unloading Document so open and implicit
write/writeln stream replacement preserve its nodes, listeners and URL.
Scope guards cover nested callbacks and ancestor teardown without blocking
other documents or manually dispatched unload events. Preserve argument
conversion and existing XML/dynamic-markup exception checks.
Add 34 Browser and main-VM regression scenarios. The 154-case WPT comparison
gains one passing case and six passing subtests with no regressions; update
the passed ledger to 9,099 cases.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,909 passed, 13 skipped). Rebuilt CLI matches the tested WPT binary.
A child javascript URL string result must unload the old document without
checking whether unloading is canceled. Reuse the existing teardown that
dispatches pagehide, visibilitychange, and unload, and cancels old timers.
Apply it to the target and its descendants, capturing document identities
before callbacks can remove or replace them.
Add three Browser integration tests covering 12 scenarios, including
nested frames, unrelated frames, non-string completion, ordinary
navigation, and attempts to navigate or schedule timers during unload.
Record the newly passing javascript-url-no-beforeunload WPT.
Validation: cargo fmt --all; workspace all-targets all-features Clippy
with -D warnings; cargo nextest run --no-fail-fast (17,904 passed,
13 skipped). Focused WPT: 110 cases, one new pass / two passing subtest
gains, no regressions.
Check the navigation load as well as the Document owner before committing
a javascript URL string result. A form submission or Location navigation
started during script execution must keep its pending request.
Add four Browser integration tests covering 13 scenarios, including GET,
POST, named targets, successor javascript URLs, unrelated frames, and
canceled navigation. Record the newly passing jsurl-form-submit WPT.
Validation: cargo fmt --all; workspace all-targets all-features Clippy
with -D warnings; cargo nextest run --no-fail-fast (17,901 passed,
13 skipped). Focused WPT: 103 cases, one new pass, no regressions.
Track complete loading separately from readyState for main and child documents, retaining the state through document.open(). Apply before-load replacement to Location assignments with the transient user activation exception, and settle inherited main load completion after a load-callback rewrite.
Keep Window.open on the generic navigation path so its history behavior remains independent of the Location API.
Cover real child history length and entry indices across parser, DOMContentLoaded, load, pageshow, and post-load document.open(), plus main navigation event classification and activation. Update the measured Location WPT results.
Initial child placeholders share a navigation index with the first committed entry and must not consume a joint-history step. Continue to the child with a real predecessor while preserving deliberately visited about:blank entries.
Cover fresh child insertion, explicit location.replace(), and a real about:blank predecessor through Browser integration tests.
Async scripts still fetching at parser EOF previously entered a queue
behind DOMContentLoaded, allowing a slow defer script to block a ready
async script or its error event. Transfer remaining async work to the
exact Document runtime producer and publish each task when its source
completes, retaining its load-delay lease.
Preserve observed async completion order across parser handoff. Add gated
success, failure, and out-of-order completion tests, and update the WPT
ledger for execution-timing/085.html.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,879 passed, 13 skipped
- 270 WPT cases: 257 to 258 passes, no case or subtest regressions
Queue iframe load delivery alongside other DOM tasks and include current
child lifecycle owners in the existing lifecycle scheduling preference.
This keeps initial load ahead of module timers that replace the document.
Cover inline, imported, external, and top-level-await modules using parent
and child timers. Check adopted-image events against the shared DOM FIFO.
Update the WPT ledgers for the three repaired delayed module-write cases.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,875 passed, 13 skipped
- 270 WPT cases: 254 to 257 passes, no case or subtest regressions
Admit DOMContentLoaded and main Window load after their parser/defer and load
prerequisites so earlier DOM tasks keep their FIFO positions. Keep interactive
readiness at parser stop, preserve child realm prerequisites, and return a load
boundary to its driver if an earlier DOM callback adds a new load delay.
Queue parser-owned external import-map errors during preparation, including
child and document.write parsers, so later dynamic errors cannot overtake them.
Cover ordering, replacement and load-delay behavior in main and child documents.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,871 passed, 13 skipped
- 270 WPT cases: 254 pass, 10 fail, 5 timeout, 1 error; one new pass and
no case-status or passing-subtest-count regressions
Reject Web IDL conversion errors through the returned Promise and decode
raster Blobs from their bytes on the blocking pool. Deliver results through
a dedicated bitmap task source bound to the exact Page and Window realm.
Retain canvas, ImageData and ImageBitmap pixel snapshots for crop, resize,
flip and alpha processing. Clear pixels on close and reject closed sources
in drawImage. Read HTML canvas dimensions from native attributes.
Cover Promise timing, pixels, intrinsic prototypes, child realm retirement,
document.open and real navigation identity collisions with Page task tests.
Promise rejection events were dispatched during microtask checkpoints or
synchronously when a late handler was attached. Queue both events on the
shared DOM-manipulation source, snapshot each realm's notification batch
at the checkpoint, and recheck handlers immediately before notification.
Keep V8 payloads in the originating Host, authorize exact Document owners
through the Page dispatcher, and restore the registered Window realm for
each event. Retire stale payloads and clear retained handles at teardown.
Exercise FIFO order across checkpoints, late handling, realm routing, and
Document replacement through the production selected-task harness. Update
existing notification fixtures and assert that suppressed rejections leave
no notification task queued.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- 254 related WPT cases: all 240 previously passing cases remain passing
- promise-rejection-events.html: 40/43 subtests pass, up from 33/43
- cargo nextest run --no-fail-fast: 17,849 passed, 13 skipped
Move execution-timing/137.html from failed to passed. The unmodified
branch baseline, the 245-case script regression run, and the final
focused rerun all pass this empty xlink:href case.
Yield live HTML script preparation to the document owner after releasing
parser borrows. Prepare from the current DOM after the guarded microtask
checkpoint, and abandon stale handoffs when that checkpoint replaces the
document. Apply the boundary to main documents, child documents, and
document.write; preserve eager parsing when no runtime owner is installed.
Admit parser async classic scripts after preparation and keep nested
script cleanup from draining microtasks while an outer script is running.
Add main/child integration coverage and update the two repaired WPT cases.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,846 passed, 13 skipped
- 245 related WPT cases: all 231 previously passing cases remain passing
- Final CLI build: both repaired WPT cases pass on the validated sources
Perform HTML script cleanup between event callbacks when the execution-context stack becomes empty, retaining currentTarget, passive state, and window.event through the checkpoint. Preserve script execution scopes during exception reporting, use the same callback boundary for Worker.onerror, and guard the complete microtask checkpoint against reentrancy.
Remove deferred window.event restoration. Update callback-order assertions and asynchronous fixtures to wait for the final event they inspect, while retaining scheduler, document-owner, and follow-up checks. Add Window, child Window, and Worker coverage for nested dispatch, listener removal in microtasks, and script versus callback exceptions.
Callback exception ordering follows Web IDL cleanup before rethrow; the local Chromium probe reports the error before that checkpoint.
WPT: 3 additional passes in the script-element microtask tests; the other 492 cases retain identical statuses and subtest results. Update the corresponding passed/failed case lists.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets --all-features -- -D warnings; cargo nextest run --no-fail-fast (17,843 passed, 13 skipped). Fresh CLI build SHA-256 matches the binary used for the 495-case WPT comparison.
Set and clear child Window event dispatch fields, and clear Worker propagation flags after native delivery. Remove once listeners before invocation and skip listeners removed by an earlier callback, including during synchronous nested dispatch.
Add Window, child Window, and Worker regression probes for active event state, redispatch after stopImmediatePropagation, and once/listener removal during nested dispatch.
Run classic script microtasks before restoring currentScript or releasing child parser nesting. Defer nested checkpoints to the outer script and wait for exception reporting before running reactions.
Cover inline and external scripts, syntax and runtime errors, document.open/write insertion points, and nested execution. Record the repaired synchronous-script bailout WPT.