Split enforcing and report-only CSP fields into independent policies at
literal commas, preserving field order and each policy's reporting data.
Trim CSP ASCII whitespace and discard policies with no parsed directives.
Cover policy intersection, duplicate directives, quoted commas, encoded
path commas, empty list members and report-only violation attribution.
Use declarative receiver checks and promise rejection adapters for container
registration and lookup methods. Convert options before invoking the Trusted
Types default policy and preserve the original conversion exceptions.
Correct getRegistration's optional-argument length and cover conversion
order, native receiver identity, and cross-realm Promise rejection.
Normalize text control selection endpoints for native deletion and movement,
including programmatic selections inside a surrogate pair. Preserve no-op
caret movements at text boundaries.
Keep selection APIs in UTF-16 code units and cover execCommand, keyboard
editing, and Shift selection for input and textarea.
Restore the _self and input button passing entries lost during replay and
classify the history back noop case as harness-stalled, matching fresh Moli
results. Keep one classification per case across all 12,936 entries.
Compared eight affected and related pages with the rebased Moli binary and
Chromium. execution-timing/102 still reports a harness timeout in both.
Serve the link-element stylesheet.py resource through the shared WPT stash.
Preserve consuming counter reads, per-ID state, cross-port sharing and HEAD
request behavior so link load-event tests observe real request counts.
Validate the fixture with 170 Python tests and the six upstream multiple-load
subtests in Moli and Chromium, then record the previously unlisted passing case.
Keep the installed owner source and JavaScript sheet while a valid link
attribute change starts a successor load. Preserve existing CSSOM edits and
prevent URL-cache hydration from replacing the current sheet prematurely.
Replacement responses detach the old sheet at installation; integrity rejection
retains it. Cover successful and failed loads, source bindings, and removal
before a queued successor response settles.
Expand {{domains[]}} to the configured primary hostname in fixture content
and sidecar headers. This fixes credentialed CORS fixtures whose allow-origin
header previously retained the literal placeholder.
Cover cross-subdomain requests and default and non-default HTTP ports.
Move the full SRI fixture to passed-cases after both engines pass all 48
subtests; the four-case integrity selection passes 68/68 in both engines.
Validate raw stylesheet response bytes and response eligibility through the
shared SRI verifier. Preserve integrity rejection in fetch terminals so failed
loads dispatch error and release their load delay without installing a sheet
or discovering imports.
Require links with integrity metadata to use the compatible fetch cache instead
of hydrating an unverified parsed source by URL. Add regressions for hashing,
CORS, service-worker filters, local data URLs, redirects, and cached loads.
Handle exact-host sources with :* in the CSP matcher instead of sending them
to URL parsing. Preserve scheme, host, path, and redirect restrictions while
rejecting invalid literal host sources.
Add coverage across resource kinds and source restrictions. Record the image
and script wildcard-port WPT files as passing, and record the two SRI files
with remaining partial-integrity failures as failing.
Validation: cargo fmt --all; workspace clippy with all targets/features and
-D warnings; full nextest (18,367 passed, 13 skipped); 69 focused CSP tests.
23 WPT cases improved from 79/94 to 86/94 subtests without new failures.
All 18 HTTP port probes match Chromium, including blocked-request counts.
Use the image element's document policy and violation recipient across realm
boundaries. Check CSP before reusing shared decoded images, and resolve meta
policy reporting groups against the owner's Reporting-Endpoints.
Cover cross-realm callers, response/meta policy isolation, report-only, bypass,
warm cache reuse, and reporting group isolation. Promote two passing WPT files.
Validation: cargo fmt --all; workspace clippy with all targets/features and
-D warnings; full nextest (18,364 passed, 13 skipped); 9 focused CSP tests.
20 WPT cases improved from 38/68 to 61/68 subtests. Two VT subtests now fail
like Chromium and remain recorded as failures; no WPT expectations changed.
Use the shared element navigation path for GET form popup submissions so the
new document retains its creator URL, policy container, and rel semantics.
Resolve child-window creators from the form's owner document, and remove the
obsolete popup path that carried only the opener flag. Apply Referrer Policy
and sanitize the source URL, honoring anchor/area policy overrides.
Exercise all seven rel combinations for form, button, and input submissions
from both top-level and HTTP-loaded iframe documents, plus cross-origin
referrer policy and fragment stripping. Record the three newly
passing form popup WPT cases.
Check the DOM, document style generations, viewport state, media environment,
and visual resources before reusing layout for synchronous geometry or input.
Keep snapshot reads available and reuse the tree while its inputs are unchanged.
Cover repeated trusted clicks on newly inserted buttons and CSSOM-only changes.
Update geometry, innerText, grid, and screencast tests for synchronous refresh,
and record nine newly passing CloseWatcher WPT cases.
Use a generated document root as the viewport input fallback, retaining the
child document and coordinate transform when an iframe has no hittable box.
Keep mouse input suppressed for roots without a box while allowing inspectors
and wheel events to target the owning Document.
Chain wheel input through embedding frames only when the child cannot consume
it, and respect overscroll containment. Cover empty, excluded and removed roots,
nested and transformed frames, viewport bounds, and wheel scroll boundaries.
Create the associated UserActivation object when its Window is initialized,
using the intrinsic interface prototype. Keep the activation state alive when
script retains a Navigator after iframe removal or Window replacement, and
release native anchors on GC or isolate teardown.
Expose the WebIDL constructor and readonly prototype accessors, preserving
native receiver checks. Refresh popup Navigators when their Window changes
so retained activation state cannot follow the replacement Window.
execCommand("copy") previously returned the user-activation flag without
firing an event or updating the clipboard. Dispatch trusted beforecopy and
copy events, honor cancellation, and copy the receiver document's selection.
Keep text-control selections per document across focus changes and reject
nested editing commands per native document. Share Window activation state
with navigator.userActivation so copying remains available after the
activating call and expires without clearing sticky activation. Read fresh
layout for DOM selection text, preserve preformatted whitespace, and use
the browser profile's clipboard line endings.
Add nine regression tests and correct the BiDi activation regression test.
Validate 38 copy-command cases, 38 existing native shortcut cases, and nine
activation-state cases against Chromium. The copy-event WPT and all 32
selection line-break subtests now pass, with no regressions in 65 WPT cases.
Dispatch trusted clipboard events for native copy, cut, and paste shortcuts,
then apply text-control edits through cancelable, typed InputEvents. Resolve
focus and selection after event listeners and preserve UTF-16 selections,
readonly and password behavior, maxlength, and single-line normalization.
Keep paste data read-only and retire clipboard DataTransfer objects after
dispatch. Use intrinsic event constructors even when page scripts replace
the globals.
Add seven regression tests for editing, cancellation, focus changes, and
clipboard data lifetime. Validate 38 native CDP scenarios against Chromium
and 63 WPT cases; textEditCommands.html now passes with no regressions in
the remaining cases.
Forward permission descriptors and states through the native automation
connection using the selected frame's origin pair and case browser context.
Verify iframe owner identity, reject stale or unavailable frames, and remove
the previous storage-access no-op.
Reset permission overrides during case cleanup and still dispose targets
when reset fails. Accept close races only after confirming the target is gone.
Validation: 613 Python tests; 63 WPT pages with no regressions (Moli 227/238,
Chromium 236/238); real permission, iframe and default-context cleanup probes.
Implement MouseEvent.getModifierState for mouse-derived events and share EventModifierInit parsing with KeyboardEvent. Read a private modifier snapshot with native receiver checks, preserve independent AltGraph and lock states, and reset the snapshot during legacy initialization.
Validation: cargo fmt --all; workspace/all-targets/all-features Clippy with warnings denied; 18,303 nextest tests pass, including 6 new regressions. The 47-page WPT comparison improves Moli from 141/158 to 147/158 with no regressions; Chromium remains 158/158.
Use case-owned input sessions while harness probes await promises, preserve native DOM geometry, and cancel concurrent actions before completing failed requests. Automatically select CDP for testdriver cases.
Validation: 605 Python tests pass; 44 WPT pages report Moli 57/69 and Chromium 69/69, with no new failures. Live probes cover trusted input, canceled editing, Escape, and target cleanup.
Expose the Window-only CloseWatcher interface through native derive bindings.
Implement requestClose(), close(), destroy(), ordered event handlers and
AbortSignal algorithms, including reentrant calls and inactive documents.
Retain the creation realm separately from the reusable WindowProxy so old
watchers cannot become active after navigation.
Add five native regressions covering lifecycle, dictionary conversion,
signal ordering, interface brands, intrinsic events and detached child realms.
Native Escape requests and activation grouping remain follow-up work.
Validation: cargo fmt --all; full workspace/all-target/all-feature Clippy
with warnings denied; cargo nextest run --no-fail-fast (18288 passed,
13 skipped). Selected browser WPTs improve from 0/30 to 25/30; the remaining
failures require native Escape handling or pass through click hit testing.
The cross-document navigation probe matches Chromium.
Use the upstream fixture server limit of 512 header lines so requests
with all 253 valid header values can reach the handler instead of
receiving HTTP 431. Cover complete GET/POST header round trips and
retain count and line-length bounds.
Validation: all 596 benchmark Python tests pass; Moli passes all 537
Headers WPT subtests. Both engines pass all 105 header value and
normalization subtests, with Chromium's 24 unrelated failures unchanged.
Route POST, OPTIONS, and extension methods through the existing header
inspection fixture, preserving response metadata and CORS behavior.
Close connections with unread uploads so header-only inspection can
respond immediately.
Validate with 45 HTTP fixture tests and the upstream header normalization
cases in Moli and Chromium (93/93 each, up from 63/93).
Use the CSS token stream to recognize empty rootMargin and scrollMargin
values, including comments, and reject unitless numbers even when zero.
Cover CSS whitespace, invalid tokens, and valid shorthand through both
the parser and IntersectionObserver constructor.
Convert option members in WebIDL order, including root brand validation and
the threshold double-or-sequence union. Propagate conversion failures before
constructor margin/range validation and retain duplicate thresholds when sorting.
Cover iterable discrimination, getter order, exception precedence, and later
getter mutations; update the existing duplicate-threshold expectations.
Return SyntaxError DOMExceptions when rootMargin or scrollMargin parsing fails.
Use the renderer intrinsic exception factory so replacing globalThis.DOMException
cannot change the result, and preserve WebIDL getter and conversion exceptions.
Add regression coverage for both margin fields and update the existing option
surface and ported fixture expectations.
Convert complete nested sequences before Headers and URLSearchParams validate pair lengths or header syntax. Use the shared sequence converter for Headers inner iterables so later conversion exceptions take precedence and indexed length access is unnecessary.
Cover conversion order, exception identity, inner iterable behavior, and extra pair elements for Headers, URLSearchParams, Request, and Response.
Stop reading or calling iterator.return when WebIDL element conversion
fails. Propagate the original exception directly, including failures in
nested sequences and interface-valued sequences.
Cover string, numeric, interface and iterator-protocol failures. Correct
old URLSearchParams closure expectations and make invalid-pair fixtures
finite so their behavior can also be checked in Chromium.
Use sequence/record discrimination for native Headers, URLSearchParams,
FormData, and URL initializers. Read the author iterator once, preserve
its result or exception, and use own record properties when it is absent.
Cover Request and Response headers, enumerable iterator symbols, and
FormData File conversion. Remove unused imports and the URL
stringification helper.
Collect all own keys, then inspect each current property descriptor before
converting its key and value. Record conversion now observes Proxy traps,
getter-driven property changes and abrupt completion in WebIDL order.
Preserve normalized duplicate-key replacement and cover Headers,
URLSearchParams and ClipboardItem, including thenable conversion order.
Correct the local URLSearchParams smoke expectation: non-enumerable symbol
keys are ignored, while enumerable symbol keys throw before value access.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,208 passed, 13 skipped
- Headers upstream WPT: 490/537 -> 504/537 (+14), no new failures
- URLSearchParams and ClipboardItem constructor regressions: 82/82
- Record behavior probes: 5/5 in Moli and Chromium
- Local URLSearchParams smoke: 26/26 in Moli; changed symbol checks: 2/2
in both engines. The full legacy smoke page times out in Chromium before
and after this change, so only its changed assertions claim parity.
Give Cache.put its own response admission rules: accept Response.error(),
and reject public status 206 or Vary: * before consuming the body. Keep
filtered internal response metadata available for storage and respondWith.
Reconstruct error responses without invoking the global Response
constructor and make headers on all cached responses immutable. Cover
failed replacement, streaming bodies, cloned errors and global tampering.
Carry the original response filter and validation state through Window
streams and Worker completions, including paused responses. Synthesized
responses remain basic, and already fetched bodies are not filtered by ORB
again. Keep client CORP/COEP checks against actual network response URLs.
Retain internal headers separately from the CORS public header view through
clone, deferred Cache.put, persistent Cache storage and respondWith. Match
Vary using the public header view and keep filtered cached headers immutable.
Keep internal response status, status text and headers through Window and
Worker fetch, Response.clone(), Cache storage and FetchEvent.respondWith().
This preserves CORP checks when a require-corp client receives an opaque
response from a service worker.
Keep public opaque headers empty and immutable, and use the public header
view when matching Vary in Cache. Cover streamed and materialized responses,
opaque redirects, filtered HTTP 206 responses and Vary:* cache roundtrips.
Reject invalid filtered respondWith responses before following their
restored internal Location headers.
Apply the data-scheme exception when selecting response filtering and the
observable response type. Data URL origins remain opaque, while no-cors
fetches retain their status, immutable headers and response body.
Cover Window and opaque-origin Worker fetches across request modes,
redirect modes, GET/HEAD/POST, Request clones, URL fragments, MIME types,
binary body reads, response clones and bodyUsed behavior.
Reject cross-origin HTTP(S) no-cors requests with manual or error redirect
mode before transport, CDP interception, or Service Worker dispatch in
Window and Worker fetch. Check the logical URL at the fetch entry point
so a CDP transport URL rewrite retains the original policy decision.
Cover non-redirecting responses, Request clones and init overrides,
local URL fetches, argument and abort precedence, interception ordering,
and Service Worker dispatch counts.
Route Window and Worker Fetch/XHR through per-hop authorization even for
safelisted requests. Reject unauthorized or credentialed cross-origin
redirects before contacting the next URL, strip cross-origin Authorization,
and preserve redirect origin, cookie, network-event and referrer state.
Discard unused preflight and redirect bodies without delaying the final
stream. Give each transfer private cancellation while sharing parent aborts
and only the accepted final response's completion facts. Select manual and
error modes from the redirect status before parsing Location.
Cover 930 Window/Worker Fetch and synchronous/asynchronous XHR scenarios,
including forbidden destination contact and request headers, plus transport
cancellation and referrer-policy regressions.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,188 passed, 13 skipped
- 252 CORS/Redirect/XHR WPT cases: 1,603 -> 1,841 passing subtests out of
2,007, with no newly failing cases or subtests
Serve Fetch redirect.py with upstream Origin and credentials responses,
preflight handling, query inheritance, counters, delays and form status codes.
Recognize its relative, absolute and RESOURCES_DIR references during discovery.
Cover the HTTP behavior and discovery with regressions. Verify the fixture
against upstream wptserve, including byte parsing and unread request bodies.
Combine all matching Access-Control-Allow-Origin and credentialed
Access-Control-Allow-Credentials fields before validating the response.
Empty duplicates and repeated matching values must also fail the CORS check.
Cover ordinary responses, preflight rejection, and responses after preflight
in Window and Worker Fetch plus asynchronous and synchronous XHR.