Use the native live collection queries for XML and detached HTML Documents,
with stable receiver-realm objects instead of detached snapshots.
Match HTML elements and unnamespaced href/name attributes, include area in
links, alias plugins to embeds, and keep applets permanently empty.
Cover mutation, adoption, namespace filtering, borrowed getters and receiver
validation; remove the obsolete detached collection scanners.
Parse response documents with the final response URL in the XHR creation
realm. Inherit the requester origin separately for CORS responses, and keep
relative URL resolution consistent through base insertion/removal/adoption.
Validated with cargo fmt, workspace clippy, and nextest (17991 passed,
13 skipped). All 935 contract checks pass; the 75-case WPT suite gains five
passing subtests with no regressions. Chromium passes all 61 new checks.
Record the URL creator's storage key and browser partition independently of
its backing Blob, and check authorization atomically with URL removal.
Use the Worker's environment key and share opaque-origin nonce allocation
between Windows and Workers so unrelated opaque origins cannot collide.
Validated with cargo fmt, workspace clippy, and nextest (17990 passed,
13 skipped). Cross-global revoke WPT passes 3/3; all 874 contract checks pass,
with no regressions across the 68-case WPT suite.
Read headers and signal through exception-preserving helpers. Capture
conversion exceptions around Window and Worker fetch argument parsing so
rejected promises retain the original thrown value, including primitives,
instead of replacing it with a TypeError or starting a request.
Cover constructor and fetch exception identity, unused input bodies, no
network dispatch, and cross-realm Promise ownership.
Validation: cargo fmt, workspace Clippy with warnings denied, and nextest
(17987 passed, 13 skipped). 68 upstream WPT cases show no regressions.
All 832 additional checks pass, including the eight pre-existing getter
exception failures identified during the preceding blob URL fix.
Capture shared blob bytes when Request is constructed or XHR is opened,
and retain the entry through cloning, Window/Worker fetches, and request
interception. Fresh URLs and reopened XHRs still observe revocation.
Private isolate-scoped carriers release their references on GC or isolate
teardown, while requests survive cleanup of the creating realm.
Validation: cargo fmt, workspace Clippy with warnings denied, and nextest
(17986 passed, 13 skipped). Fixes seven upstream WPT failures; 58 cases
show no regressions. Additional contract checks improve from 332 to 440
out of 448; eight pre-existing getter-exception failures remain separate.
Use libcurl's explicit-empty header syntax and keep upload Content-Type
suppression internal to the transport, including custom methods. Remove
Fetch and XHR suppression sentinels from Window and Worker request paths.
Cover empty versus absent values on the wire for streaming and buffered
auth transport, plus Window/Worker Fetch, Request clones and async/sync XHR.
Validation: cargo fmt --all; workspace clippy with all targets/features
and -D warnings; cargo nextest run --no-fail-fast (17975 passed, 13 skipped).
37 WPT cases gain 12 passing subtests without regressions; all 1540
additional request-header checks pass.
Normalize header values after WebIDL conversion and state checks, reject
invalid names or values with SyntaxError, and ignore forbidden request
headers. Combine repeated values with comma-space while retaining the
first name and empty list members.
Keep quoted strings intact in the shared method-override filter so quoted
commas do not turn permitted values into forbidden methods. Cover error
ordering, reentrant argument conversion, and actual outgoing headers.
Validation: cargo fmt --all, workspace all-targets/all-features Clippy with
-D warnings, and cargo nextest run --no-fail-fast pass (17973 passed,
13 skipped). The 37-case WPT check improves from 22 to 27 passing cases and
300 to 388 passing assertions, without regressions. All 20 supplemental
Window/Worker checks pass across synchronous and asynchronous XHR.
Implement xhr/resources/inspect-headers.py with raw header names, duplicate
values, byte-preserving filters, and its upstream CORS response headers.
Support HEAD, uploads, and custom methods through the shared XHR dispatch,
and recognize the supported fixture references during case selection.
Validation: all 516 benchmark unit tests pass. 84 HTTP comparisons match
the unmodified upstream handler. With the same Moli binary, 31 WPT cases
improve from 9 to 18 passes and from 80 to 114 passing subtests, without
regressions.
Implement requri.py and redirect.py with their upstream query, status,
Location, delay, and method behavior. Preserve raw request URIs and allow
redirect responses before the upload completes.
Recognize supported XHR references during case selection and cover the
fixtures through real HTTP requests.
Validation: all 510 benchmark unit tests pass. With the unchanged Moli
binary, 17 WPT cases improve from 6 to 9 passes and 72 to 79 passing
subtests; both redirected Worker harnesses now execute their assertions.
Serialize Response.url and XMLHttpRequest.responseURL without fragments
at the getter boundary. Keep stored response URLs and Request.url intact,
including query strings and percent-encoded hash characters.
Cover Fetch clones and asynchronous/synchronous XHR for local responses.
Use a fresh random UUID for each object URL, as required by File API,
instead of a decimal counter. Reuse the existing UUID generator and check
for collisions while holding the URL map lock.
Extend the lifetime regression to cover independently revoking two URLs
created from the same Blob.
Realm tokens are allocated per JsContextHost while the BlobStore is shared.
Match both resource owner and realm token when retiring ordinary or isolated
window contexts, including failed bootstrap cleanup.
Extend the store and renderer regressions for colliding lifetime identifiers
across two owners and two live VMs.
Reading contentWindow on an iframe in a windowless document must not make
its synthetic child document visible. Determine browsing-context ownership
from native top-level, child frame, and popup registrations, preserving
the document's retained visibility state separately from defaultView.
Cover both getter access orders, nested synthetic frames, and cross-realm
visibility/defaultView getters on live documents and popups.
Follow-up to #501.
Resolve no-cors Fetch responses at their headers in Window and worker realms, preserving header policy checks and cancellation. Keep suspect opaque bytes in capture storage until the existing ORB classifier approves them, including clone, CacheStorage and service-worker consumers.
Verify unfinished streams and real connection closure across Window, child Window and worker realms. All workspace gates pass; 83 related WPT cases gain two abort subtests without regressions.
Preserve the selected request body stream in Window and Worker fetch
bindings. Reject with the original abort reason before synchronously
canceling a readable upload, and handle the internal cancellation promise
without replacing the fetch rejection or reading public Promise methods.
Merge RequestInit bodies and inherited methods before validating the
effective request. Nullish body overrides inherit the input body; invalid
stream options and GET/HEAD bodies fail construction before cancellation.
Remove the obsolete public then shim and its classified direct-call entry.
Add regression coverage for cancellation timing, reason identity, source
errors, body selection, reentry, validation and modified public intrinsics
in Window, iframe and Worker contexts.
Validation: fmt and strict workspace Clippy passed; nextest passed 17,962
tests with 13 skipped. All 12 pre-abort and 3 ordinary-upload CLI probe
groups passed. The 83-case WPT selection gains two passing subtests with
no regressions or new failures; whole-case counts remain 77 pass / 6 fail.
Allocate Body.arrayBuffer() and Body.bytes() results in the receiver's
creation context for buffered, author-stream and pending network bodies.
Retain that context across asynchronous completion and recognize readable
bodies by their internal brand when methods are borrowed across realms.
Add Request/Response regression coverage for both iframe borrowing
directions, null bodies, byte contents, asynchronous and cloned streams,
prototype changes, network rewrapping, and original stream error identity.
Validation: cargo fmt --all; strict workspace Clippy; nextest (17,958
passed, 13 skipped). The 81-case WPT selection improves from 73 to 75
passing cases with no regressions or new failed subtests. All four CLI
regression groups pass (176 checks).
Read and copy Uint8Array chunks through native chunk, close, and error
steps, then materialize using the shared body conversions. Defer internal
streaming callbacks until response registration and network delivery finish.
Remove the JavaScript bootstrap consumer and intrinsic reader plumbing.
Cover inherited then handlers, chunk mutation and detachment, exceptions,
and constructor tampering in window, iframe, and worker contexts.
Model trickle.py by draining the request body, delaying headers and body
chunks, and writing TEST_TRICKLE lines according to ms/count. Preserve the
optional Content-Type omission and close-delimited response framing.
Exercise supported methods, defaults, duplicate/invalid parameters,
progressive delivery, and both fixed-length and chunked uploads.
Validation: 221 Python tests passed. With the same Moli binary, 16 WPT
cases add two passing cases and eight passing subtests, with no regressions.
No Rust source or build metadata changed.
Decode buffered and fetched text/json bodies with UTF-8 BOM removal before
creating strings or invoking the native JSON parser. Remove exactly one
initial BOM, retain replacement behavior for malformed UTF-8, and keep
binary/form consumers unchanged. Borrow valid UTF-8 while materializing.
Cover constructed Request/Response bodies, delayed ReadableStream input,
data URLs, and chunked HTTP in window, child frame, and worker realms.
Include split/repeated BOMs, UTF-16 markers and MIME charset, SyntaxError,
clone ordering, raw bytes, and URL-encoded/multipart form values.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,946 passed, 13 skipped); 9/9 CLI probes. A 40-case WPT comparison adds
four passing cases and ten passing subtests without regressions.
Retain ReadableStream BodyInit values instead of extracting empty bytes.
Validate stream construction options, tee cloned bodies with independent
chunks, and proxy inherited stream-only bodies while immediately marking
the original disturbed. Use native stream operations for cancellation and
error propagation even when public stream methods are overridden.
Cover consumption, clone isolation, validation, errors, and cancellation in
window, child-frame, and worker realms. The 37-case Fetch WPT comparison
adds four passing cases and six passing subtests without regressions;
public stream tee still passes all 52 subtests.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,943 passed, 13 skipped); 9/9 CLI regression probes.
Carry request methods through buffered, streaming, Worker, and navigation
preload response creation. Discard public and filtered internal bodies before
registering streams, so null bodies remain reusable through reads, clones,
and aborts while empty GET responses keep their streams.
Cover real HTTP responses in Window, iframe, and Worker and verify pending
body sources do not retain late chunks or terminal events.
Validation: cargo fmt --all; workspace Clippy with all targets/features and
-D warnings; nextest 17,940 passed, 13 skipped. Focused WPT comparison gained
2 complete cases and 20 subtests across 69 cases with no new failures.
Use the shared ImageData interface identity during BitmapSource conversion
and remove Fetch interface imports made obsolete by replayed body changes.
Preserve the existing bitmap conversion order.
Derive Body usability and bodyUsed from native stream state, preserve reader locks during consumption, and keep null bodies reusable. Reject unusable stream inputs and propagate body conversion failures through their promises.
Use native reader operations without forcing lazy Streams interfaces during bootstrap. Cover buffered and streaming bodies in Window, iframe, and Worker; update null-body expectations and WPT pass lists.
Worker abort events now use the signal realm's intrinsic Event constructor
and carry the native trust flag, including timeout and stream cancellation.
Share AbortSignal dispatch setup and cleanup between Window and Worker.
Script dispatch validates Event state and clears trust, active redispatch
throws, and completion clears currentTarget, eventPhase, the event path,
and propagation flags. Pre-stopped events skip listeners and remain reusable.
Cover controller, composite, stream and timeout events with overwritten or
missing public constructors, plus synthetic dispatch and native event reuse,
in Window, child frames and dedicated workers.
Flatten composite signals to their ordered original sources in Window and
Worker stores. Mark every dependent aborted with the first reason before
running abort algorithms or listeners, then dispatch in dependency order.
Snapshot listeners when each event starts and remove signal-bound DOM
listeners before its abort event. Cover nested and overlapping sources,
reentrant cancellation, empty composites, reason identity, and listener
changes in Window, child frames, and dedicated workers.
Use intrinsic constructors in the Navigation or history entry target realm
for navigate, currententrychange, navigatesuccess, navigateerror and dispose.
Create history entries in their owning window even when methods are borrowed
from another window. Preserve native navigate event trust and construct
navigation abort controllers and trusted abort events through intrinsics.
Add three Browser integration tests covering 14 cross-window, joint-history
and cross-document flows, including throwing public constructor getters.
The same fixture matches Chrome in all 14 flows.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17918 passed, 13 skipped). The 334-case WPT comparison gains two passing
cases and two subtests without regressions; passed ledger is 9107.
Use the active child Document's native complete-load state when choosing
whether iframe src navigation replaces the current history entry. This
covers parser, DOMContentLoaded, load and pageshow callbacks despite an
already complete readyState, while retaining post-load push behavior.
Add Browser coverage for 14 src assignment and setAttribute flows. Update
two existing history expectations for src changes from iframe load
callbacks, independently confirmed with their HTML fixtures in Chrome.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17915 passed, 13 skipped). The 222-case WPT comparison gains three passing
cases and three subtests without regressions; passed ledger is 9105.
Run cross-document child traversal through the shared unload tree after
its root navigation checks, retaining visibility transitions and one
unload lifecycle per retiring document and descendant.
Apply native Window lifecycle events' legacy Document target override
explicitly, and reset trust for script-dispatched events. Add Browser
coverage for native versus synthetic dispatch, nested history/navigation
roundtrips, and same-document traversal.
Validation: cargo fmt --all; workspace Clippy with all targets/features
and -D warnings; nextest (17913 passed, 13 skipped). 213 WPT cases gained
one passing case and two passing subtests with no regressions. Seven
matching Chrome fixture flows passed.
Snapshot retiring frame documents and finish their beforeunload phase before
actual unload delivery. Preserve ancestor unload counters through descendant
callbacks and check exact owners before dispatching further events.
Retain visibility state on the native Document and dispatch trusted, bubbling
visibilitychange events through the host event path. Use native unload
counters to suppress navigation during visibility and ancestor callbacks;
cancel each retiring window's timers after its unload.
Eight Browser integration tests cover 50 scenarios. The 181-case WPT
comparison gains two passing cases and seven passing subtests without
regressions; update the passed ledger to 9,101 cases.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,910 passed, 13 skipped). Rebuilt CLI matches the tested WPT binary.
Keep a native counter for each unloading Document so open and implicit
write/writeln stream replacement preserve its nodes, listeners and URL.
Scope guards cover nested callbacks and ancestor teardown without blocking
other documents or manually dispatched unload events. Preserve argument
conversion and existing XML/dynamic-markup exception checks.
Add 34 Browser and main-VM regression scenarios. The 154-case WPT comparison
gains one passing case and six passing subtests with no regressions; update
the passed ledger to 9,099 cases.
Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings; cargo nextest run --no-fail-fast
(17,909 passed, 13 skipped). Rebuilt CLI matches the tested WPT binary.
A child javascript URL string result must unload the old document without
checking whether unloading is canceled. Reuse the existing teardown that
dispatches pagehide, visibilitychange, and unload, and cancels old timers.
Apply it to the target and its descendants, capturing document identities
before callbacks can remove or replace them.
Add three Browser integration tests covering 12 scenarios, including
nested frames, unrelated frames, non-string completion, ordinary
navigation, and attempts to navigate or schedule timers during unload.
Record the newly passing javascript-url-no-beforeunload WPT.
Validation: cargo fmt --all; workspace all-targets all-features Clippy
with -D warnings; cargo nextest run --no-fail-fast (17,904 passed,
13 skipped). Focused WPT: 110 cases, one new pass / two passing subtest
gains, no regressions.
Check the navigation load as well as the Document owner before committing
a javascript URL string result. A form submission or Location navigation
started during script execution must keep its pending request.
Add four Browser integration tests covering 13 scenarios, including GET,
POST, named targets, successor javascript URLs, unrelated frames, and
canceled navigation. Record the newly passing jsurl-form-submit WPT.
Validation: cargo fmt --all; workspace all-targets all-features Clippy
with -D warnings; cargo nextest run --no-fail-fast (17,901 passed,
13 skipped). Focused WPT: 103 cases, one new pass, no regressions.
Track complete loading separately from readyState for main and child documents, retaining the state through document.open(). Apply before-load replacement to Location assignments with the transient user activation exception, and settle inherited main load completion after a load-callback rewrite.
Keep Window.open on the generic navigation path so its history behavior remains independent of the Location API.
Cover real child history length and entry indices across parser, DOMContentLoaded, load, pageshow, and post-load document.open(), plus main navigation event classification and activation. Update the measured Location WPT results.
Initial child placeholders share a navigation index with the first committed entry and must not consume a joint-history step. Continue to the child with a real predecessor while preserving deliberately visited about:blank entries.
Cover fresh child insertion, explicit location.replace(), and a real about:blank predecessor through Browser integration tests.
Async scripts still fetching at parser EOF previously entered a queue
behind DOMContentLoaded, allowing a slow defer script to block a ready
async script or its error event. Transfer remaining async work to the
exact Document runtime producer and publish each task when its source
completes, retaining its load-delay lease.
Preserve observed async completion order across parser handoff. Add gated
success, failure, and out-of-order completion tests, and update the WPT
ledger for execution-timing/085.html.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,879 passed, 13 skipped
- 270 WPT cases: 257 to 258 passes, no case or subtest regressions
Queue iframe load delivery alongside other DOM tasks and include current
child lifecycle owners in the existing lifecycle scheduling preference.
This keeps initial load ahead of module timers that replace the document.
Cover inline, imported, external, and top-level-await modules using parent
and child timers. Check adopted-image events against the shared DOM FIFO.
Update the WPT ledgers for the three repaired delayed module-write cases.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,875 passed, 13 skipped
- 270 WPT cases: 254 to 257 passes, no case or subtest regressions
Admit DOMContentLoaded and main Window load after their parser/defer and load
prerequisites so earlier DOM tasks keep their FIFO positions. Keep interactive
readiness at parser stop, preserve child realm prerequisites, and return a load
boundary to its driver if an earlier DOM callback adds a new load delay.
Queue parser-owned external import-map errors during preparation, including
child and document.write parsers, so later dynamic errors cannot overtake them.
Cover ordering, replacement and load-delay behavior in main and child documents.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 17,871 passed, 13 skipped
- 270 WPT cases: 254 pass, 10 fail, 5 timeout, 1 error; one new pass and
no case-status or passing-subtest-count regressions
Reject Web IDL conversion errors through the returned Promise and decode
raster Blobs from their bytes on the blocking pool. Deliver results through
a dedicated bitmap task source bound to the exact Page and Window realm.
Retain canvas, ImageData and ImageBitmap pixel snapshots for crop, resize,
flip and alpha processing. Clear pixels on close and reject closed sources
in drawImage. Read HTML canvas dimensions from native attributes.
Cover Promise timing, pixels, intrinsic prototypes, child realm retirement,
document.open and real navigation identity collisions with Page task tests.