Commit Graph
1492 Commits
Author SHA1 Message Date
ldm0 64fec4e200 fix(csp): retain all violations in document policy checks 2026-09-23 00:14:06 +08:00
ldm0 862711b980 fix(csp): parse each policy in response header lists
Split enforcing and report-only CSP fields into independent policies at
literal commas, preserving field order and each policy's reporting data.
Trim CSP ASCII whitespace and discard policies with no parsed directives.

Cover policy intersection, duplicate directives, quoted commas, encoded
path commas, empty list members and report-only violation attribution.
2026-09-23 00:14:06 +08:00
ldm0 0364afd264 fix(service-worker): apply WebIDL promise operation semantics
Use declarative receiver checks and promise rejection adapters for container
registration and lookup methods. Convert options before invoking the Trusted
Types default policy and preserve the original conversion exceptions.

Correct getRegistration's optional-argument length and cover conversion
order, native receiver identity, and cross-realm Promise rejection.
2026-09-23 00:14:06 +08:00
ldm0 6caa312731 fix(editing): preserve surrogate pairs in text control actions
Normalize text control selection endpoints for native deletion and movement,
including programmatic selections inside a surrogate pair. Preserve no-op
caret movements at text boundaries.

Keep selection APIs in UTF-16 code units and cover execCommand, keyboard
editing, and Shift selection for input and textarea.
2026-09-23 00:14:06 +08:00
ldm0 5c5d0110fa test(wpt): reconcile case lists after main rebase
Restore the _self and input button passing entries lost during replay and
classify the history back noop case as harness-stalled, matching fresh Moli
results. Keep one classification per case across all 12,936 entries.

Compared eight affected and related pages with the rebased Moli binary and
Chromium. execution-timing/102 still reports a harness timeout in both.
2026-09-23 00:14:06 +08:00
ldm0 fb65684f51 fix(wpt): implement the link stylesheet request counter
Serve the link-element stylesheet.py resource through the shared WPT stash.
Preserve consuming counter reads, per-ID state, cross-port sharing and HEAD
request behavior so link load-event tests observe real request counts.

Validate the fixture with 170 Python tests and the six upstream multiple-load
subtests in Moli and Chromium, then record the previously unlisted passing case.
2026-09-23 00:14:06 +08:00
ldm0 3971bf6574 fix(cssom): retain link sheets until replacement loads
Keep the installed owner source and JavaScript sheet while a valid link
attribute change starts a successor load. Preserve existing CSSOM edits and
prevent URL-cache hydration from replacing the current sheet prematurely.

Replacement responses detach the old sheet at installation; integrity rejection
retains it. Cover successful and failed loads, source bindings, and removal
before a queued successor response settles.
2026-09-23 00:14:06 +08:00
ldm0 6506357554 fix(wpt): substitute the primary domain in fixture templates
Expand {{domains[]}} to the configured primary hostname in fixture content
and sidecar headers. This fixes credentialed CORS fixtures whose allow-origin
header previously retained the literal placeholder.

Cover cross-subdomain requests and default and non-default HTTP ports.

Move the full SRI fixture to passed-cases after both engines pass all 48
subtests; the four-case integrity selection passes 68/68 in both engines.
2026-09-23 00:14:06 +08:00
ldm0 ce00b57648 fix(stylesheet): enforce integrity before CSSOM installation
Validate raw stylesheet response bytes and response eligibility through the
shared SRI verifier. Preserve integrity rejection in fetch terminals so failed
loads dispatch error and release their load delay without installing a sheet
or discovering imports.

Require links with integrity metadata to use the compatible fetch cache instead
of hydrating an unverified parsed source by URL. Add regressions for hashing,
CORS, service-worker filters, local data URLs, redirects, and cached loads.
2026-09-23 00:14:06 +08:00
ldm0 7faa0b3cee fix(csp): require every integrity hash to match policy 2026-09-23 00:14:06 +08:00
ldm0 20b448a54f fix(csp): match wildcard ports on exact hosts
Handle exact-host sources with :* in the CSP matcher instead of sending them
to URL parsing. Preserve scheme, host, path, and redirect restrictions while
rejecting invalid literal host sources.

Add coverage across resource kinds and source restrictions. Record the image
and script wildcard-port WPT files as passing, and record the two SRI files
with remaining partial-integrity failures as failing.

Validation: cargo fmt --all; workspace clippy with all targets/features and
-D warnings; full nextest (18,367 passed, 13 skipped); 69 focused CSP tests.
23 WPT cases improved from 79/94 to 86/94 subtests without new failures.
All 18 HTTP port probes match Chromium, including blocked-request counts.
2026-09-23 00:14:06 +08:00
ldm0 b1e13278e6 fix(csp): enforce image policies for the owning document
Use the image element's document policy and violation recipient across realm
boundaries. Check CSP before reusing shared decoded images, and resolve meta
policy reporting groups against the owner's Reporting-Endpoints.

Cover cross-realm callers, response/meta policy isolation, report-only, bypass,
warm cache reuse, and reporting group isolation. Promote two passing WPT files.

Validation: cargo fmt --all; workspace clippy with all targets/features and
-D warnings; full nextest (18,364 passed, 13 skipped); 9 focused CSP tests.
20 WPT cases improved from 38/68 to 61/68 subtests. Two VT subtests now fail
like Chromium and remain recorded as failures; no WPT expectations changed.
2026-09-23 00:14:06 +08:00
ldm0 3fa6610ae1 fix(forms): preserve popup navigation source and referrer
Use the shared element navigation path for GET form popup submissions so the
new document retains its creator URL, policy container, and rel semantics.
Resolve child-window creators from the form's owner document, and remove the
obsolete popup path that carried only the opener flag. Apply Referrer Policy
and sanitize the source URL, honoring anchor/area policy overrides.

Exercise all seven rel combinations for form, button, and input submissions
from both top-level and HTTP-loaded iframe documents, plus cross-origin
referrer policy and fragment stripping. Record the three newly
passing form popup WPT cases.
2026-09-23 00:14:06 +08:00
ldm0 f4d34a69ae fix(layout): refresh geometry after DOM and style changes
Check the DOM, document style generations, viewport state, media environment,
and visual resources before reusing layout for synchronous geometry or input.
Keep snapshot reads available and reuse the tree while its inputs are unchanged.

Cover repeated trusted clicks on newly inserted buttons and CSSOM-only changes.
Update geometry, innerText, grid, and screencast tests for synchronous refresh,
and record nine newly passing CloseWatcher WPT cases.
2026-09-23 00:14:06 +08:00
ldm0 5d88d0cdd9 fix(input): preserve document ownership in empty iframe viewports
Use a generated document root as the viewport input fallback, retaining the
child document and coordinate transform when an iframe has no hittable box.
Keep mouse input suppressed for roots without a box while allowing inspectors
and wheel events to target the owning Document.

Chain wheel input through embedding frames only when the child cannot consume
it, and respect overscroll containment. Cover empty, excluded and removed roots,
nested and transformed frames, viewport bounds, and wheel scroll boundaries.
2026-09-23 00:14:06 +08:00
ldm0 8f2c55610d fix(navigator): retain UserActivation state with its Window
Create the associated UserActivation object when its Window is initialized,
using the intrinsic interface prototype. Keep the activation state alive when
script retains a Navigator after iframe removal or Window replacement, and
release native anchors on GC or isolate teardown.

Expose the WebIDL constructor and readonly prototype accessors, preserving
native receiver checks. Refresh popup Navigators when their Window changes
so retained activation state cannot follow the replacement Window.
2026-09-23 00:14:06 +08:00
ldm0 5c8c50d478 fix(editing): implement native execCommand text copying
execCommand("copy") previously returned the user-activation flag without
firing an event or updating the clipboard. Dispatch trusted beforecopy and
copy events, honor cancellation, and copy the receiver document's selection.

Keep text-control selections per document across focus changes and reject
nested editing commands per native document. Share Window activation state
with navigator.userActivation so copying remains available after the
activating call and expires without clearing sticky activation. Read fresh
layout for DOM selection text, preserve preformatted whitespace, and use
the browser profile's clipboard line endings.

Add nine regression tests and correct the BiDi activation regression test.
Validate 38 copy-command cases, 38 existing native shortcut cases, and nine
activation-state cases against Chromium. The copy-event WPT and all 32
selection line-break subtests now pass, with no regressions in 65 WPT cases.
2026-09-23 00:14:06 +08:00
ldm0 dd349bdb27 fix(input): implement native clipboard shortcuts for text controls
Dispatch trusted clipboard events for native copy, cut, and paste shortcuts,
then apply text-control edits through cancelable, typed InputEvents. Resolve
focus and selection after event listeners and preserve UTF-16 selections,
readonly and password behavior, maxlength, and single-line normalization.

Keep paste data read-only and retire clipboard DataTransfer objects after
dispatch. Use intrinsic event constructors even when page scripts replace
the globals.

Add seven regression tests for editing, cancellation, focus changes, and
clipboard data lifetime. Validate 38 native CDP scenarios against Chromium
and 63 WPT cases; textEditCommands.html now passes with no regressions in
the remaining cases.
2026-09-23 00:14:06 +08:00
ldm0 bc0f8dbfb0 fix(cdp): preserve session routing for child default bindings 2026-09-23 00:14:06 +08:00
ldm0 be65a191eb fix(benchmark): route WPT permission changes through CDP
Forward permission descriptors and states through the native automation
connection using the selected frame's origin pair and case browser context.
Verify iframe owner identity, reject stale or unavailable frames, and remove
the previous storage-access no-op.

Reset permission overrides during case cleanup and still dispose targets
when reset fails. Accept close races only after confirming the target is gone.

Validation: 613 Python tests; 63 WPT pages with no regressions (Moli 227/238,
Chromium 236/238); real permission, iframe and default-context cleanup probes.
2026-09-23 00:14:06 +08:00
ldm0 3aec916d9b fix(events): preserve keyboard and mouse modifier state
Implement MouseEvent.getModifierState for mouse-derived events and share EventModifierInit parsing with KeyboardEvent. Read a private modifier snapshot with native receiver checks, preserve independent AltGraph and lock states, and reset the snapshot during legacy initialization.

Validation: cargo fmt --all; workspace/all-targets/all-features Clippy with warnings denied; 18,303 nextest tests pass, including 6 new regressions. The 47-page WPT comparison improves Moli from 141/158 to 147/158 with no regressions; Chromium remains 158/158.
2026-09-23 00:14:06 +08:00
ldm0 3c82924f70 fix(benchmark): dispatch WPT input through native CDP
Use case-owned input sessions while harness probes await promises, preserve native DOM geometry, and cancel concurrent actions before completing failed requests. Automatically select CDP for testdriver cases.

Validation: 605 Python tests pass; 44 WPT pages report Moli 57/69 and Chromium 69/69, with no new failures. Live probes cover trusted input, canceled editing, Escape, and target cleanup.
2026-09-23 00:14:06 +08:00
ldm0 1aefad2767 feat(close-watcher): handle native Escape with activation groups 2026-09-23 00:14:06 +08:00
ldm0 5d227304f9 feat(close-watcher): implement programmatic lifecycle
Expose the Window-only CloseWatcher interface through native derive bindings.
Implement requestClose(), close(), destroy(), ordered event handlers and
AbortSignal algorithms, including reentrant calls and inactive documents.
Retain the creation realm separately from the reusable WindowProxy so old
watchers cannot become active after navigation.

Add five native regressions covering lifecycle, dictionary conversion,
signal ordering, interface brands, intrinsic events and detached child realms.
Native Escape requests and activation grouping remain follow-up work.

Validation: cargo fmt --all; full workspace/all-target/all-feature Clippy
with warnings denied; cargo nextest run --no-fail-fast (18288 passed,
13 skipped). Selected browser WPTs improve from 0/30 to 25/30; the remaining
failures require native Escape handling or pass through click hit testing.
The cross-document navigation probe matches Chromium.
2026-09-23 00:14:05 +08:00
ldm0 bb654f6a23 fix(benchmark): match wptserve HTTP header count limit
Use the upstream fixture server limit of 512 header lines so requests
with all 253 valid header values can reach the handler instead of
receiving HTTP 431. Cover complete GET/POST header round trips and
retain count and line-length bounds.

Validation: all 596 benchmark Python tests pass; Moli passes all 537
Headers WPT subtests. Both engines pass all 105 header value and
normalization subtests, with Chromium's 24 unrelated failures unchanged.
2026-09-23 00:14:05 +08:00
ldm0 ebaee0b161 fix(benchmark): serve Fetch header inspection for all methods
Route POST, OPTIONS, and extension methods through the existing header
inspection fixture, preserving response metadata and CORS behavior.
Close connections with unread uploads so header-only inspection can
respond immediately.

Validate with 45 HTTP fixture tests and the upstream header normalization
cases in Moli and Chromium (93/93 each, up from 63/93).
2026-09-23 00:14:05 +08:00
ldm0 c4447bccf8 fix(intersection-observer): parse margin emptiness from CSS tokens
Use the CSS token stream to recognize empty rootMargin and scrollMargin
values, including comments, and reject unitless numbers even when zero.
Cover CSS whitespace, invalid tokens, and valid shorthand through both
the parser and IntersectionObserver constructor.
2026-09-23 00:14:05 +08:00
ldm0 77bfdea307 fix(intersection-observer): convert options before validating thresholds
Convert option members in WebIDL order, including root brand validation and
the threshold double-or-sequence union. Propagate conversion failures before
constructor margin/range validation and retain duplicate thresholds when sorting.

Cover iterable discrimination, getter order, exception precedence, and later
getter mutations; update the existing duplicate-threshold expectations.
2026-09-23 00:14:05 +08:00
ldm0 261412a4ee fix(intersection-observer): throw DOM syntax errors for invalid margins
Return SyntaxError DOMExceptions when rootMargin or scrollMargin parsing fails.
Use the renderer intrinsic exception factory so replacing globalThis.DOMException
cannot change the result, and preserve WebIDL getter and conversion exceptions.

Add regression coverage for both margin fields and update the existing option
surface and ported fixture expectations.
2026-09-23 00:14:05 +08:00
ldm0 dbb0948e45 fix(webidl): convert initializer sequences before validating pairs
Convert complete nested sequences before Headers and URLSearchParams validate pair lengths or header syntax. Use the shared sequence converter for Headers inner iterables so later conversion exceptions take precedence and indexed length access is unnecessary.

Cover conversion order, exception identity, inner iterable behavior, and extra pair elements for Headers, URLSearchParams, Request, and Response.
2026-09-23 00:14:05 +08:00
ldm0 0d15b6275f fix(webidl): propagate sequence errors without closing iterators
Stop reading or calling iterator.return when WebIDL element conversion
fails. Propagate the original exception directly, including failures in
nested sequences and interface-valued sequences.

Cover string, numeric, interface and iterator-protocol failures. Correct
old URLSearchParams closure expectations and make invalid-pair fixtures
finite so their behavior can also be checked in Chromium.
2026-09-23 00:14:05 +08:00
ldm0 ccd4e35b1f fix(webidl): honor initializer iterators on platform objects
Use sequence/record discrimination for native Headers, URLSearchParams,
FormData, and URL initializers. Read the author iterator once, preserve
its result or exception, and use own record properties when it is absent.

Cover Request and Response headers, enumerable iterator symbols, and
FormData File conversion. Remove unused imports and the URL
stringification helper.
2026-09-23 00:14:05 +08:00
ldm0 ded94488a8 fix(webidl): preserve record conversion order and symbol keys
Collect all own keys, then inspect each current property descriptor before
converting its key and value. Record conversion now observes Proxy traps,
getter-driven property changes and abrupt completion in WebIDL order.

Preserve normalized duplicate-key replacement and cover Headers,
URLSearchParams and ClipboardItem, including thenable conversion order.

Correct the local URLSearchParams smoke expectation: non-enumerable symbol
keys are ignored, while enumerable symbol keys throw before value access.

Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,208 passed, 13 skipped
- Headers upstream WPT: 490/537 -> 504/537 (+14), no new failures
- URLSearchParams and ClipboardItem constructor regressions: 82/82
- Record behavior probes: 5/5 in Moli and Chromium
- Local URLSearchParams smoke: 26/26 in Moli; changed symbol checks: 2/2
  in both engines. The full legacy smoke page times out in Chromium before
  and after this change, so only its changed assertions claim parity.
2026-09-23 00:14:05 +08:00
ldm0 7d82b9862b fix(fetch): inherit intrinsic Headers prototype methods
Bind Headers storage objects to the realm's intrinsic Headers.prototype
and reuse its declared operations. Request, Response, fetch and Cache
headers now share operation identity and observe prototype method updates.

Cover replaced global constructors, Response getter/clone receiver realms,
and inherited method descriptors and iterator aliases.

Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,205 passed, 13 skipped
- Cache upstream WPT: 86/250 -> 180/250 (+94), no new failures
- Headers upstream WPT: 490/537, no regressions
- Prototype probes: 81/81; descriptor probes: 2/2 in Moli and Chromium
- Cache admission and Service Worker response regressions: 84/84 and 384/384
2026-09-23 00:14:05 +08:00
ldm0 f75013bafd fix(cache): validate stored responses and preserve network errors
Give Cache.put its own response admission rules: accept Response.error(),
and reject public status 206 or Vary: * before consuming the body. Keep
filtered internal response metadata available for storage and respondWith.

Reconstruct error responses without invoking the global Response
constructor and make headers on all cached responses immutable. Cover
failed replacement, streaming bodies, cloned errors and global tampering.
2026-09-23 00:14:05 +08:00
ldm0 d8b07e357e fix(fetch): preserve service worker response types and CORS headers
Carry the original response filter and validation state through Window
streams and Worker completions, including paused responses. Synthesized
responses remain basic, and already fetched bodies are not filtered by ORB
again. Keep client CORP/COEP checks against actual network response URLs.

Retain internal headers separately from the CORS public header view through
clone, deferred Cache.put, persistent Cache storage and respondWith. Match
Vary using the public header view and keep filtered cached headers immutable.
2026-09-23 00:14:05 +08:00
ldm0 fd78eb20da fix(fetch): preserve opaque response metadata through service workers
Keep internal response status, status text and headers through Window and
Worker fetch, Response.clone(), Cache storage and FetchEvent.respondWith().
This preserves CORP checks when a require-corp client receives an opaque
response from a service worker.

Keep public opaque headers empty and immutable, and use the public header
view when matching Vary in Cache. Cover streamed and materialized responses,
opaque redirects, filtered HTTP 206 responses and Vary:* cache roundtrips.

Reject invalid filtered respondWith responses before following their
restored internal Location headers.
2026-09-23 00:14:05 +08:00
ldm0 6363e3b20e fix(fetch): keep data URL responses basic across request modes
Apply the data-scheme exception when selecting response filtering and the
observable response type. Data URL origins remain opaque, while no-cors
fetches retain their status, immutable headers and response body.

Cover Window and opaque-origin Worker fetches across request modes,
redirect modes, GET/HEAD/POST, Request clones, URL fragments, MIME types,
binary body reads, response clones and bodyUsed behavior.
2026-09-23 00:14:05 +08:00
ldm0 d6ab49efe2 fix(fetch): reject non-follow cross-origin no-cors requests
Reject cross-origin HTTP(S) no-cors requests with manual or error redirect
mode before transport, CDP interception, or Service Worker dispatch in
Window and Worker fetch. Check the logical URL at the fetch entry point
so a CDP transport URL rewrite retains the original policy decision.

Cover non-redirecting responses, Request clones and init overrides,
local URL fetches, argument and abort precedence, interception ordering,
and Service Worker dispatch counts.
2026-09-23 00:14:05 +08:00
ldm0 f146d1d8c0 fix(worker): make global origin replaceable 2026-09-23 00:14:05 +08:00
ldm0 c8be37263e fix(fetch): preserve URLs on opaque redirect responses 2026-09-23 00:14:05 +08:00
ldm0 7351aa152a fix(wpt): honor CORS opt-in for common redirect fixtures 2026-09-23 00:14:05 +08:00
ldm0 8149a939fd fix(wpt): serve redirects with an empty Location header 2026-09-23 00:14:05 +08:00
ldm0 774f3ba0a3 fix(wpt): serve XHR PUT and wildcard preflight fixtures 2026-09-23 00:14:05 +08:00
ldm0 f317cb1d64 fix(fetch): preserve redirect mode when filtering responses 2026-09-23 00:14:05 +08:00
ldm0 7da8439d5b fix(fetch): enforce CORS checks on every browser redirect
Route Window and Worker Fetch/XHR through per-hop authorization even for
safelisted requests. Reject unauthorized or credentialed cross-origin
redirects before contacting the next URL, strip cross-origin Authorization,
and preserve redirect origin, cookie, network-event and referrer state.

Discard unused preflight and redirect bodies without delaying the final
stream. Give each transfer private cancellation while sharing parent aborts
and only the accepted final response's completion facts. Select manual and
error modes from the redirect status before parsing Location.

Cover 930 Window/Worker Fetch and synchronous/asynchronous XHR scenarios,
including forbidden destination contact and request headers, plus transport
cancellation and referrer-policy regressions.

Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,188 passed, 13 skipped
- 252 CORS/Redirect/XHR WPT cases: 1,603 -> 1,841 passing subtests out of
  2,007, with no newly failing cases or subtests
2026-09-23 00:14:05 +08:00
ldm0 f3bb739c83 fix(wpt): model Fetch redirect fixtures
Serve Fetch redirect.py with upstream Origin and credentials responses,
preflight handling, query inheritance, counters, delays and form status codes.
Recognize its relative, absolute and RESOURCES_DIR references during discovery.

Cover the HTTP behavior and discovery with regressions. Verify the fixture
against upstream wptserve, including byte parsing and unread request bodies.
2026-09-23 00:14:05 +08:00
ldm0 cb24a93207 fix(cors): validate complete origin and credentials fields
Combine all matching Access-Control-Allow-Origin and credentialed
Access-Control-Allow-Credentials fields before validating the response.
Empty duplicates and repeated matching values must also fail the CORS check.

Cover ordinary responses, preflight rejection, and responses after preflight
in Window and Worker Fetch plus asynchronous and synchronous XHR.
2026-09-23 00:13:44 +08:00
ldm0 c3c9c22381 fix(wpt): serve Fetch preflight fixtures 2026-09-23 00:13:44 +08:00
ldm0 db97c36bb4 fix(cors): validate complete preflight permission lists 2026-09-23 00:13:44 +08:00