Decode text and JSON consumers with UTF-8 BOM removal while retaining the existing JSON parser and all binary consumers. Cover constructed Request/Response bodies and asynchronously split Response streams, repeated and misplaced BOMs, malformed UTF-8, UTF-16 markers, MIME charset independence, SyntaxError, and raw binary/form values.
Source: 3c3bd08064
Accept the 253-header WPT fixtures using the same bounded 512-header limit as wptserve. Exercise both request and response parsing while retaining count and line-length rejection.
Source: 8aa635acc5
Serve the dynamic stylesheet counter and consume counts when queried. Share counts across fixture ports while isolating them from Fetch stash entries. Cover HEAD requests, per-ID separation, and read-and-clear behavior.
Source: 79a997c10d
Share parsed SRI metadata with CSP hash-source matching. Require a nonempty
set whose every supported hash is authorized, while response verification
continues to use the strongest hashes. Cover malformed tokens, hash aliases,
weaker hashes, and literal digest matching.
Source: f960314f49
Run the complete all profile against Moli 1a12ee01e and WPT db95fafd1
using the release binary, CDP mode, and 50 parallel workers.
The 12,874 cases include 206 newly discovered cases: 165 pass, 37 fail,
and 4 time out. Overall: 8,729 pass, 3,800 fail, 283 timeout,
53 harness-stalled, 9 error, and no crashes or missing cases.
Preserve the full run classifications, including 12 existing cases that
became passing and 6 previously passing cases that did not pass this run.
Validation: full run completed in 727.89 seconds; all case lists match
the result matrix exactly, with no duplicates or omitted cases.
Use byte-only decomposition for Response and NavigationResponse instead of
discarding the text returned by into_parts(). Module, dedicated worker, and
service worker consumers now transfer the existing exact byte allocation.
Verify storage transfer for UTF-8 and non-UTF-8 payloads.
Source: e32030e484
Close retired mailboxes and cancel their generations under the registry lock, then release callback captures after unlocking. Publish environment invalidations through the registry while retaining only notifiers that need waking.
Cover callback destruction during unregister and replacement, lock-free owner wake, and delayed wake after teardown. Validated with cargo fmt --all, all-target all-feature Clippy, 52 related tests over 5 stress iterations, and the complete Nextest suite (17505 passed, 13 skipped).
Keep request origin independent of URL resolution and referrer context,
including local blob fetches and inherited or sandboxed srcdoc documents.
Reject missing browser origins at the resource client boundary and retain
one Request across Service Worker redirects and network fallback.
Cover dispatch rejection, wire Origin/Cookie headers, memory-cache
partitioning and preserved Service Worker request metadata.
Validation: workspace fmt and Clippy passed; Nextest passed 17,517 tests
with 13 existing skips. Renderer test debug symbols were disabled to fit
available build memory; tests and debug assertions were unchanged.
Name coalesced work by the native caches it invalidates, and document that the Worker armed bit tracks the outstanding fallback message rather than mailbox contents.
Consolidate Date/Intl options regressions into named cases and fold time-first legacy dates into the shared parsing matrix, retaining their inputs and native-semantic assertions.
Publish typed invalidation flags under the environment lock and wake isolate owners only after releasing it. Bound page and worker notification work while preserving command FIFO, teardown safety, and observation ordering.
Remove stale wrapper-era dependencies and terminology, and add mailbox race and CDP burst regressions.
Generate Origin independently of browser destination metadata, and attach script
metadata at classic, module, and preload request builders. Share redirect URL-list
rules across request generation and response validation, and remove final-only
CORS validation from manifests, stylesheets, and request interception.
Reject failed CORS checks even without supported integrity metadata. Preserve CSP
reporting before dynamic script fetches and use committed Window origins for
srcdoc and sandboxed child script/module requests.
Add wire-level Origin, Cookie, and Fetch Metadata regressions, plus manifest,
stylesheet CSSOM, CSP, and child module/preload coverage.
Keep redirect history in Request so Service Worker handoffs, network
redirects, preflights, Origin serialization, cookies, and TLS credentials
share the same state. Avoid reusing another request's response URL list
from the renderer memory cache.
Validate and filter network responses using their full history while
preserving readable Service Worker response filters across streaming and
buffered delivery. Returning to the initiating origin keeps network CORS
tainting; worker-produced responses retain their own filtering.
Add wire-header, credentials, cache, and worker response regressions, and
correct the local Fetch/XHR redirect fixtures to authorize and expose CORS
responses after a cross-origin round trip.
Distinguish network, service worker, and browser-internal redirects so synthetic responses are not subjected to network CORS checks. Preserve every hop for redirect taint and Origin validation, including across navigation response conversions.
Add seven cross-origin service worker script scenarios and guard CORS checks for cached network redirects without ExtraInfo. The new integration regression fails before the fix and passes afterward.
Validated with cargo fmt --all, workspace Clippy across all targets and features with warnings denied, and cargo nextest run --no-fail-fast: 17459 passed, 13 skipped. Used one build job for the full test run after a parallel-build rustc process was killed.
Refresh the all profile on 59e1af954 against WPT db95fafd1 using CDP, 50 workers, and an 800x600 viewport at DPR 1.
Record all 12,668 cases: 8,558 pass, 3,760 fail, 284 timeout, 52 harness-stalled, and 14 error; no crashes or missing cases. Compared with the previous lists, 36 cases became passing and 8 became non-passing.
Preserve the full-run observations. In two focused runs at parallelism 8 and one serial run, seven of the eight previously passing cases passed each time. The CSP javascript URL inheritance case failed all three rechecks because the expected report was absent; its underlying cause remains undiagnosed.
Preserve response filtering through script and service worker loading, validate CORS authorization across redirects, and reject opaque responses before computing supported integrity digests. Keep empty and unsupported metadata behavior unchanged.
Add parser, dynamic script, module, and service worker regressions covering 39 scenarios. Validated with cargo fmt --all, full workspace Clippy, and cargo nextest run --no-fail-fast (17457 passed, 13 skipped).
Make process environment owners non-cloneable RAII authorities, share session admission while preserving failed and no-op outcomes, and consolidate duplicate isolate-entry handling. Keep read-only owner queries side-effect-free and add lifecycle regressions.
Remove the Date/Intl wrappers, custom date parser and per-Page replay state. Keep exclusive locale/timezone ownership in a process controller and refresh existing Page and Worker isolates through generation-bound notifications and observation boundaries, including nested Inspector pauses.
Release claims on session/target/context retirement, retain native coercion and locale matching, and cover lifecycle restoration with Rust, BiDi and process-isolated CDP regressions.
Handle Unicode and legacy date inputs without unsafe slicing or timezone corruption. Normalize ICU locale IDs with the bundled ICU library and forward Intl options without violating frozen-object invariants. Add renderer regressions and process-isolated CDP input coverage.