Expand {{domains[]}} to the configured primary hostname in fixture content
and sidecar headers. This fixes credentialed CORS fixtures whose allow-origin
header previously retained the literal placeholder.
Cover cross-subdomain requests and default and non-default HTTP ports.
Move the full SRI fixture to passed-cases after both engines pass all 48
subtests; the four-case integrity selection passes 68/68 in both engines.
Validate raw stylesheet response bytes and response eligibility through the
shared SRI verifier. Preserve integrity rejection in fetch terminals so failed
loads dispatch error and release their load delay without installing a sheet
or discovering imports.
Require links with integrity metadata to use the compatible fetch cache instead
of hydrating an unverified parsed source by URL. Add regressions for hashing,
CORS, service-worker filters, local data URLs, redirects, and cached loads.
Handle exact-host sources with :* in the CSP matcher instead of sending them
to URL parsing. Preserve scheme, host, path, and redirect restrictions while
rejecting invalid literal host sources.
Add coverage across resource kinds and source restrictions. Record the image
and script wildcard-port WPT files as passing, and record the two SRI files
with remaining partial-integrity failures as failing.
Validation: cargo fmt --all; workspace clippy with all targets/features and
-D warnings; full nextest (18,367 passed, 13 skipped); 69 focused CSP tests.
23 WPT cases improved from 79/94 to 86/94 subtests without new failures.
All 18 HTTP port probes match Chromium, including blocked-request counts.
Use the image element's document policy and violation recipient across realm
boundaries. Check CSP before reusing shared decoded images, and resolve meta
policy reporting groups against the owner's Reporting-Endpoints.
Cover cross-realm callers, response/meta policy isolation, report-only, bypass,
warm cache reuse, and reporting group isolation. Promote two passing WPT files.
Validation: cargo fmt --all; workspace clippy with all targets/features and
-D warnings; full nextest (18,364 passed, 13 skipped); 9 focused CSP tests.
20 WPT cases improved from 38/68 to 61/68 subtests. Two VT subtests now fail
like Chromium and remain recorded as failures; no WPT expectations changed.
Use the shared element navigation path for GET form popup submissions so the
new document retains its creator URL, policy container, and rel semantics.
Resolve child-window creators from the form's owner document, and remove the
obsolete popup path that carried only the opener flag. Apply Referrer Policy
and sanitize the source URL, honoring anchor/area policy overrides.
Exercise all seven rel combinations for form, button, and input submissions
from both top-level and HTTP-loaded iframe documents, plus cross-origin
referrer policy and fragment stripping. Record the three newly
passing form popup WPT cases.
Use a generated document root as the viewport input fallback, retaining the
child document and coordinate transform when an iframe has no hittable box.
Keep mouse input suppressed for roots without a box while allowing inspectors
and wheel events to target the owning Document.
Chain wheel input through embedding frames only when the child cannot consume
it, and respect overscroll containment. Cover empty, excluded and removed roots,
nested and transformed frames, viewport bounds, and wheel scroll boundaries.
Create the associated UserActivation object when its Window is initialized,
using the intrinsic interface prototype. Keep the activation state alive when
script retains a Navigator after iframe removal or Window replacement, and
release native anchors on GC or isolate teardown.
Expose the WebIDL constructor and readonly prototype accessors, preserving
native receiver checks. Refresh popup Navigators when their Window changes
so retained activation state cannot follow the replacement Window.
execCommand("copy") previously returned the user-activation flag without
firing an event or updating the clipboard. Dispatch trusted beforecopy and
copy events, honor cancellation, and copy the receiver document's selection.
Keep text-control selections per document across focus changes and reject
nested editing commands per native document. Share Window activation state
with navigator.userActivation so copying remains available after the
activating call and expires without clearing sticky activation. Read fresh
layout for DOM selection text, preserve preformatted whitespace, and use
the browser profile's clipboard line endings.
Add nine regression tests and correct the BiDi activation regression test.
Validate 38 copy-command cases, 38 existing native shortcut cases, and nine
activation-state cases against Chromium. The copy-event WPT and all 32
selection line-break subtests now pass, with no regressions in 65 WPT cases.
Dispatch trusted clipboard events for native copy, cut, and paste shortcuts,
then apply text-control edits through cancelable, typed InputEvents. Resolve
focus and selection after event listeners and preserve UTF-16 selections,
readonly and password behavior, maxlength, and single-line normalization.
Keep paste data read-only and retire clipboard DataTransfer objects after
dispatch. Use intrinsic event constructors even when page scripts replace
the globals.
Add seven regression tests for editing, cancellation, focus changes, and
clipboard data lifetime. Validate 38 native CDP scenarios against Chromium
and 63 WPT cases; textEditCommands.html now passes with no regressions in
the remaining cases.
Forward permission descriptors and states through the native automation
connection using the selected frame's origin pair and case browser context.
Verify iframe owner identity, reject stale or unavailable frames, and remove
the previous storage-access no-op.
Reset permission overrides during case cleanup and still dispose targets
when reset fails. Accept close races only after confirming the target is gone.
Validation: 613 Python tests; 63 WPT pages with no regressions (Moli 227/238,
Chromium 236/238); real permission, iframe and default-context cleanup probes.
Implement MouseEvent.getModifierState for mouse-derived events and share EventModifierInit parsing with KeyboardEvent. Read a private modifier snapshot with native receiver checks, preserve independent AltGraph and lock states, and reset the snapshot during legacy initialization.
Validation: cargo fmt --all; workspace/all-targets/all-features Clippy with warnings denied; 18,303 nextest tests pass, including 6 new regressions. The 47-page WPT comparison improves Moli from 141/158 to 147/158 with no regressions; Chromium remains 158/158.
Use case-owned input sessions while harness probes await promises, preserve native DOM geometry, and cancel concurrent actions before completing failed requests. Automatically select CDP for testdriver cases.
Validation: 605 Python tests pass; 44 WPT pages report Moli 57/69 and Chromium 69/69, with no new failures. Live probes cover trusted input, canceled editing, Escape, and target cleanup.
Expose the Window-only CloseWatcher interface through native derive bindings.
Implement requestClose(), close(), destroy(), ordered event handlers and
AbortSignal algorithms, including reentrant calls and inactive documents.
Retain the creation realm separately from the reusable WindowProxy so old
watchers cannot become active after navigation.
Add five native regressions covering lifecycle, dictionary conversion,
signal ordering, interface brands, intrinsic events and detached child realms.
Native Escape requests and activation grouping remain follow-up work.
Validation: cargo fmt --all; full workspace/all-target/all-feature Clippy
with warnings denied; cargo nextest run --no-fail-fast (18288 passed,
13 skipped). Selected browser WPTs improve from 0/30 to 25/30; the remaining
failures require native Escape handling or pass through click hit testing.
The cross-document navigation probe matches Chromium.
Use the upstream fixture server limit of 512 header lines so requests
with all 253 valid header values can reach the handler instead of
receiving HTTP 431. Cover complete GET/POST header round trips and
retain count and line-length bounds.
Validation: all 596 benchmark Python tests pass; Moli passes all 537
Headers WPT subtests. Both engines pass all 105 header value and
normalization subtests, with Chromium's 24 unrelated failures unchanged.
Route POST, OPTIONS, and extension methods through the existing header
inspection fixture, preserving response metadata and CORS behavior.
Close connections with unread uploads so header-only inspection can
respond immediately.
Validate with 45 HTTP fixture tests and the upstream header normalization
cases in Moli and Chromium (93/93 each, up from 63/93).
Use the CSS token stream to recognize empty rootMargin and scrollMargin
values, including comments, and reject unitless numbers even when zero.
Cover CSS whitespace, invalid tokens, and valid shorthand through both
the parser and IntersectionObserver constructor.
Convert option members in WebIDL order, including root brand validation and
the threshold double-or-sequence union. Propagate conversion failures before
constructor margin/range validation and retain duplicate thresholds when sorting.
Cover iterable discrimination, getter order, exception precedence, and later
getter mutations; update the existing duplicate-threshold expectations.
Return SyntaxError DOMExceptions when rootMargin or scrollMargin parsing fails.
Use the renderer intrinsic exception factory so replacing globalThis.DOMException
cannot change the result, and preserve WebIDL getter and conversion exceptions.
Add regression coverage for both margin fields and update the existing option
surface and ported fixture expectations.
Convert complete nested sequences before Headers and URLSearchParams validate pair lengths or header syntax. Use the shared sequence converter for Headers inner iterables so later conversion exceptions take precedence and indexed length access is unnecessary.
Cover conversion order, exception identity, inner iterable behavior, and extra pair elements for Headers, URLSearchParams, Request, and Response.
Stop reading or calling iterator.return when WebIDL element conversion
fails. Propagate the original exception directly, including failures in
nested sequences and interface-valued sequences.
Cover string, numeric, interface and iterator-protocol failures. Correct
old URLSearchParams closure expectations and make invalid-pair fixtures
finite so their behavior can also be checked in Chromium.
Use sequence/record discrimination for native Headers, URLSearchParams,
FormData, and URL initializers. Read the author iterator once, preserve
its result or exception, and use own record properties when it is absent.
Cover Request and Response headers, enumerable iterator symbols, and
FormData File conversion. Remove unused imports and the URL
stringification helper.
Collect all own keys, then inspect each current property descriptor before
converting its key and value. Record conversion now observes Proxy traps,
getter-driven property changes and abrupt completion in WebIDL order.
Preserve normalized duplicate-key replacement and cover Headers,
URLSearchParams and ClipboardItem, including thenable conversion order.
Correct the local URLSearchParams smoke expectation: non-enumerable symbol
keys are ignored, while enumerable symbol keys throw before value access.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,208 passed, 13 skipped
- Headers upstream WPT: 490/537 -> 504/537 (+14), no new failures
- URLSearchParams and ClipboardItem constructor regressions: 82/82
- Record behavior probes: 5/5 in Moli and Chromium
- Local URLSearchParams smoke: 26/26 in Moli; changed symbol checks: 2/2
in both engines. The full legacy smoke page times out in Chromium before
and after this change, so only its changed assertions claim parity.
Give Cache.put its own response admission rules: accept Response.error(),
and reject public status 206 or Vary: * before consuming the body. Keep
filtered internal response metadata available for storage and respondWith.
Reconstruct error responses without invoking the global Response
constructor and make headers on all cached responses immutable. Cover
failed replacement, streaming bodies, cloned errors and global tampering.
Carry the original response filter and validation state through Window
streams and Worker completions, including paused responses. Synthesized
responses remain basic, and already fetched bodies are not filtered by ORB
again. Keep client CORP/COEP checks against actual network response URLs.
Retain internal headers separately from the CORS public header view through
clone, deferred Cache.put, persistent Cache storage and respondWith. Match
Vary using the public header view and keep filtered cached headers immutable.
Keep internal response status, status text and headers through Window and
Worker fetch, Response.clone(), Cache storage and FetchEvent.respondWith().
This preserves CORP checks when a require-corp client receives an opaque
response from a service worker.
Keep public opaque headers empty and immutable, and use the public header
view when matching Vary in Cache. Cover streamed and materialized responses,
opaque redirects, filtered HTTP 206 responses and Vary:* cache roundtrips.
Reject invalid filtered respondWith responses before following their
restored internal Location headers.
Apply the data-scheme exception when selecting response filtering and the
observable response type. Data URL origins remain opaque, while no-cors
fetches retain their status, immutable headers and response body.
Cover Window and opaque-origin Worker fetches across request modes,
redirect modes, GET/HEAD/POST, Request clones, URL fragments, MIME types,
binary body reads, response clones and bodyUsed behavior.
Reject cross-origin HTTP(S) no-cors requests with manual or error redirect
mode before transport, CDP interception, or Service Worker dispatch in
Window and Worker fetch. Check the logical URL at the fetch entry point
so a CDP transport URL rewrite retains the original policy decision.
Cover non-redirecting responses, Request clones and init overrides,
local URL fetches, argument and abort precedence, interception ordering,
and Service Worker dispatch counts.
Route Window and Worker Fetch/XHR through per-hop authorization even for
safelisted requests. Reject unauthorized or credentialed cross-origin
redirects before contacting the next URL, strip cross-origin Authorization,
and preserve redirect origin, cookie, network-event and referrer state.
Discard unused preflight and redirect bodies without delaying the final
stream. Give each transfer private cancellation while sharing parent aborts
and only the accepted final response's completion facts. Select manual and
error modes from the redirect status before parsing Location.
Cover 930 Window/Worker Fetch and synchronous/asynchronous XHR scenarios,
including forbidden destination contact and request headers, plus transport
cancellation and referrer-policy regressions.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 18,188 passed, 13 skipped
- 252 CORS/Redirect/XHR WPT cases: 1,603 -> 1,841 passing subtests out of
2,007, with no newly failing cases or subtests
Serve Fetch redirect.py with upstream Origin and credentials responses,
preflight handling, query inheritance, counters, delays and form status codes.
Recognize its relative, absolute and RESOURCES_DIR references during discovery.
Cover the HTTP behavior and discovery with regressions. Verify the fixture
against upstream wptserve, including byte parsing and unread request bodies.
Combine all matching Access-Control-Allow-Origin and credentialed
Access-Control-Allow-Credentials fields before validating the response.
Empty duplicates and repeated matching values must also fail the CORS check.
Cover ordinary responses, preflight rejection, and responses after preflight
in Window and Worker Fetch plus asynchronous and synchronous XHR.
Share Fetch body filtering with local responses and XHR, complete null-body streams at headers, and preserve replacement request progress when old completions arrive.
Cover Window and Worker response types, synthetic null-body statuses, empty response event order, and request reuse.
Ignore unsupported responseType values without resetting the selected type,
including historical moz-* tokens. Convert the value to a string before XHR
state checks and preserve conversion exceptions and reentrant state changes.
A missing setter argument is converted like undefined and ignored.
Validate native getter/setter receivers before conversion. Ignore document in
Workers before checking LOADING or DONE, while retaining InvalidStateError and
InvalidAccessError for valid values where the XHR setter algorithm requires it.
Cover Window and Worker conversion, borrowed accessors, forged receivers,
response identity, and open/send reentrancy over real HTTP. Correct the legacy
test expectations for invalid enum assignments and historical moz-* tokens.
https://webidl.spec.whatwg.org/#dfn-attribute-setterhttps://xhr.spec.whatwg.org/#the-responsetype-attribute
Validation: cargo fmt --all; workspace Clippy with all targets/features and
-D warnings; cargo nextest run --no-fail-fast (18161 passed, 13 skipped).
192 upstream WPT cases: 175 -> 178 pass, 726 -> 748 passing subtests,
no new regressions. Window and Worker responseType matrices both pass 50/50.
Reject invalid HTTP method tokens with SyntaxError and forbidden methods with
SecurityError. Share validation with Fetch while preserving its TypeError
behavior. Validate native receivers before argument conversion and document
activity before method and URL processing.
Create exceptions in the invoked method realm, including when DOMException is
first materialized after WindowProxy detachment. Resolve its prototype from
the realm-owned intrinsic registry. Preserve pending requests, headers,
responses, and events when open fails.
Cover Window and Worker conversion order, native receiver identity, cross-realm
inactive documents, retired cold realms, and request preservation on the wire.
Validation: cargo fmt --all; workspace Clippy with all targets/features and
-D warnings; cargo nextest run --no-fail-fast (18157 passed, 13 skipped).
189 upstream WPT cases: 171 -> 174 pass, 624 -> 642 passing subtests. Four
cases improve. open-url-multi-window-6.htm now fails its caller-realm
constructor assertion; two popup probes using the method-realm expectation
improve from fail to pass. The original WPT and raw comparison are unchanged.
WebIDL specifies the method realm for DOMExceptions:
https://webidl.spec.whatwg.org/#js-creating-throwing-exceptions
Complete active page XHRs with the request-error steps when a response
stream fails after delivering partial data. Reset the response and dispatch
error/loadend instead of leaving the request in LOADING.
Check the request identity for stream and body-materialization failures so
queued errors cannot overwrite an aborted or reopened XHR. Exercise real
truncated Content-Length and malformed chunked responses, including abort,
open, and resend before a queued failure is delivered.
Validation: cargo fmt --all; full workspace clippy with warnings denied;
cargo nextest run --no-fail-fast (18,153 passed, 13 skipped).
Focused upstream WPT: 83/88 cases and 133/143 subtests pass, up from 82/88
and 132/143, with no regressions. Page malformed-body error now passes.
Serve the upstream malformed chunk sequence and infinite redirect loop
instead of returning Python source. Preserve redirect parameters and origin,
explicit raw body writes, and supported endpoint filtering.
Validation: all 550 benchmark tests pass, including raw wire and partial
HTTP body decoding regressions. With the same Moli binary, 88 focused WPT
cases improve from 77 to 82 passes (127 to 132 of 143 subtests).
The corrected fixture also exposes a page XHR bug: malformed-body handling
now times out instead of failing on unexpected load. Its streaming failure
branch records the network error without dispatching XHR error/loadend;
that engine fix follows separately. The worker variant now passes.
Route URL and network policy rejections through the pending worker XHR
completion queue so send() returns before error delivery. Immediate abort()
and open() can cancel the queued failure. Validate request identity before
applying a completion so old failures cannot overwrite a new send.
Cover six rejection causes, listeners installed after send, microtask abort,
reopen and resend, synchronous NetworkError, and duplicate failure records.
Validation: cargo fmt --all; full workspace clippy with warnings denied;
cargo nextest run --no-fail-fast (18,152 passed, 13 skipped).
Focused upstream WPT: 77/86 cases and 127/141 subtests pass, up from 76/86
and 126/141, with no regressions. Worker abort-with-error now passes.
Observe transmitted request bytes in the native transport and queue upload
progress and completion in the owning page or worker realm. Cover empty
bodies, resumed requests, redirects, and partial uploads without fabricating
completion during send().
Mark uploads complete before final callbacks and reject stale events after
abort or reopen. Preserve upload error events and update local smoke tests
to collect the full final upload task.
Validation: cargo fmt --all; full workspace clippy with warnings denied;
cargo nextest run --no-fail-fast (18,148 passed, 13 skipped).
Focused upstream WPT: 67/73 passing versus 65/73, 114/125 subtests versus
112/125, with no regressions.
Snapshot upload listeners before send callbacks and carry the preflight
requirement through page and worker requests, redirects, interception,
authentication continuations, and service worker network fallback. Route
synchronous worker XHR through the shared CORS transport and validate
preflight responses using the actual request credentials mode.
Add real HTTP regressions for listener timing, sync and async requests,
redirects, interception, credentials, and denied preflights. Update existing
PageVm response fixtures to authorize preflights before testing the actual
CORS response and to respect the shared redirect limit.
Validation: cargo fmt --all; full workspace clippy with warnings denied;
cargo nextest run --no-fail-fast (18,142 passed, 13 skipped). The 73 selected
upstream WPT cases retain 65 passing cases and 112/125 passing subtests,
with no regressions.
Dispatch XHR loadstart before upload loadstart and report zero initially transmitted bytes. Snapshot registered upload listeners before callbacks and preserve requests reopened or aborted during startup in both page and worker realms.
Use non-computable zero-total upload events and update local compatibility expectations. Real transport-driven upload progress and completion remain a separate follow-up.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets --all-features -- -D warnings; cargo nextest run --no-fail-fast (18139 passed, 13 skipped). Selected upstream WPT: 51 to 59 passing cases out of 66; 68 to 80 passing subtests out of 89, with no regressions.
Match the upstream corsenabled.py response headers, request metadata reflection, query-controlled delay and additional Content-Type allowance. Recognize exact relative and absolute fixture references during XHR case selection.
Validation: all 545 Python tests pass, including six new fixture tests. With an unchanged engine binary, nine CORS WPT cases improve from 1 to 6 passing and subtests from 14 to 36 of 44, with no regressions.