Run main-document dynamic inline scripts through the shared classic-script
executor in the document's main world. Keep currentScript set while parse and
runtime exceptions are synchronously reported, then restore the outer script
without propagating the exception through the inserting DOM operation.
Cover nested error handlers, thrown object identity,
re-insertion, shadow trees, borrowed child-realm insertion methods, isolated
worlds, and deferred microtasks. Remove the redundant inline load-event
scheduling entry point.
Implement Window and Document location PutForwards by retrieving the
receiver's Location and assigning the original value to href. This keeps
conversion, exceptions, and navigation in the target href setter's realm
and preserves null and undefined as URL inputs. Remove the Location attribute
conversion helper's nullish-to-empty shortcut so href receives their string values.
Use the native Document brand for both own location accessors, reject
windowless null Locations before conversion, and keep constructed Document
setters on the same forwarding path. Share native cross-origin Location
assignment between Proxy calls and PutForwards so nested native setters keep
their current realm instead of the incumbent author script realm.
Cover borrowed setters and getters across three realms, forged and Proxy
receivers, conversion order, intrinsic error constructors, and nullish URL
navigation. The official cross-realm Location WPT improves from 9/11 to
10/11; the remaining cross-origin Window invalid-receiver failure is
unchanged.
Use the existing returns_promise binding adapter for fetch and createImageBitmap.
Check native Window branding and same-origin access before argument conversion,
then reject invocation errors with intrinsic Promises in the function realm.
Keep Fetch's captured Window binding across observable conversions. Recognize
retained native globals and their registry retirement before private-slot reads
so detached callbacks preserve their shutdown rejection. Skip unhandled-rejection
notifications in retired native contexts before reading global scope markers.
Cover cross-realm and discarded receivers, registered native Window wrappers,
author Proxies, constructor tampering, and conversion exception identity.
Update the cross-origin Fetch regression to the Web IDL/WPT rejection contract.
Check native Window receivers and same-origin access before argument conversion
in synchronous methods. Report operation receiver errors in the callee realm,
while retaining captured Window ownership and registered native wrappers.
Keep Worker base64 operations on their shared conversion path. Cover forged and
author Proxy receivers, borrowed calls, conversion ordering, cross-realm errors,
Worker base64 behavior, and EventTarget methods on genuine Nodes.
Use the shared native Window and same-origin receiver check before timer, animation, idle, and microtask methods convert arguments or queue work. Reject foreign Windows and forged receivers in the callee realm while preserving genuine borrowed calls and native bridge wrappers.
Cover all nine methods across parent/child realms, conversion ordering, author Proxies, nullish defaults, and discarded foreign Windows. Keep Worker callbacks and task lifetime handling intact.
Validation: cargo fmt --all; strict workspace/all-targets/all-features Clippy; full nextest 19586 passed, 13 skipped; focused 1357 passed; 863 browser checks agree with Chromium. Official cross-origin WPT remains 78/90 with its first restricted-method failure advancing to getComputedStyle; 14 control pages are unchanged.
Use native Window receiver and same-origin checks before reading protected
attributes, replacing properties, converting strings, or creating storage
and Trusted Types objects. Share event and viewport getter callbacks across
runtime and template bindings. Materialize caches in the receiver realm and
stop name mutations when string conversion throws.
Cover cross-realm exception constructors, author Proxies and forged
receivers, replaceable attributes, and nested current-event restoration.
Read permitted Window getters through the native cross-origin surface,
preserving Window and Location identity across navigation and disposal.
Share alias callbacks between runtime and template initialization, and
apply native brand and same-origin checks to protected Window accessors.
Cover cross-realm receivers, forged objects and author Proxies, author
property replacements, location conversion, and iframe lifecycle in a
391-check regression fixture.
Share Window brand and same-origin checks across event accessors and frameElement.
Honor LegacyLenientThis for mouseenter/mouseleave without suppressing cross-origin
SecurityErrors, and preserve errors in the accessor realm.
Recognize native bridge and popup Window wrappers through their existing Web IDL
brand. Copying __moliNativeBridge or wrapping a Window in an author Proxy must not
validate a receiver or mutate the Window's handlers.
Add a reusable browser regression for 868 assertions covering receiver identity,
handler ownership, realm errors, author traps, and navigation, plus a native
Window wrapper regression.
Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 19,582 passed, 13 skipped
- Focused workspace tests: 1,048 passed
- Browser regression: 868/868 in Moli and Chromium; native Window wrapper probe passed
- Unmodified cross-origin-objects WPT: 75/90 -> 78/90; exactly the three
LegacyLenientThis failures removed, with 12 existing failures unchanged
- Eight surrounding WPT controls unchanged
CrossOriginPropertyFallback requires undefined for Symbol.toStringTag as well
as Symbol.hasInstance and Symbol.isConcatSpreadable. Use that common value in
every cross-origin Window/Location surface instead of exposing interface tags.
Same-origin objects retain their normal Window and Location tags.
Cover fallback reads, descriptors, presence, mutation rejection, caller realms,
origin transitions, retained Location objects, and removed Windows. Update the
older migration test to expect the cross-origin Object class string.
Validation: cargo fmt --all; strict workspace Clippy with all targets/features;
cargo nextest run --no-fail-fast. All 232 browser regression checks pass. The
official cross-origin-objects.html improves from 69/90 to 75/90, with the other
15 failures unchanged; eight WPT control pages retain their baseline results.
Repeated src assignments must schedule navigation even from the child Window
or iframe element load handler. The old early return left the WPT cross-origin
object test waiting forever on the final frame in its reload barrier. Remove
the load-dispatch tracking and URL helpers used only by that guard.
Cover property and setAttribute writes, same-origin and cross-origin owner
loads, and child Window loads. Check asynchronous navigation, fresh Documents,
stable WindowProxy identity, and loaded descendants across three reloads.
Validation: cargo fmt --all; strict workspace Clippy with all targets/features;
cargo nextest run --no-fail-fast. All 84 browser regression assertions pass in
Moli and Chromium. The unmodified cross-origin-objects.html completes all 90
subtests (69 pass, 21 fail); the same 21 failures reproduce on the old binary
when test reload calls are diagnostically deferred. Eight WPT control pages
retain exactly their baseline results.
Select the first direct child with each target name before checking its
original origin against the receiving Window. Share this lookup between
same-origin and cross-origin named access, including live name changes and
navigation, without applying document.domain relaxation.
Allow named children to shadow non-exposed properties and the then fallback,
while keeping cross-origin IDL properties first. Use canonical array-index
parsing so names such as 01 and 4294967295 remain available by name.
Cover property descriptors, duplicate names, origin changes, renaming,
removal, and indexed WindowProxy identities. The named-access WPT now passes
all three subtests. An older frameElement WPT assumes that cross-origin
name-only lookup succeeds, contrary to this requirement; direct and indexed
frameElement security checks remain covered separately.
Use the native top WindowProxy for cross-origin parent/top references and
resolve indexed and named children from the live browsing context. Preserve
window identities through child navigation and document.domain changes,
with SecurityError for inaccessible or missing properties.
Create exposed methods and getters in the accessing realm. Weakly cache
these surfaces while retained functions trace their shared callback data,
preserving identity across garbage collection without rooting dead realms.
Cover top and nested parents, append/remove/navigation, borrowed postMessage,
function realms and caching, and document.domain transitions.
Keep cross-origin access surfaces on their owning Window globals with weak
native lookups, so retained references remain readable after retirement.
Validate the original proxy and realm before resolving child state, and prevent
old postMessage and Location receivers from targeting a reinserted iframe.
Keep current isolated-world globals valid through their native Window identity.
Add shared browser and Rust regression coverage for direct, ancestor, and
replaceChildren removal in ordinary and closed shadow trees.
Check the captured LocalWindow identity when reading parent, top, frameElement
and closed. DOM removal disconnects the container before its unload callbacks
run, while native ownership remains current until the callbacks finish.
Include shadow trees when collecting browsing contexts from disconnected
subtrees so removing a shadow host unloads and retires its frames as well.
Cover four removal operations in light and closed shadow trees, callback
visibility and Window relationships, and retained references after reattachment.
Reject retained traversal results in their original realm when the target
LocalWindow retires before the history task runs. Complete the Promise
reactions without firing navigation events or applying stale history.
Keep PageVm namespaces and exact task ownership checks when consuming the
payload, and leave classic History tasks without results as no-op cleanup.
Choose back/forward destinations from the committed current entry so
repeated pending calls share the same destination and result Promises.
Cover removed and reinserted frames, same- and cross-document traversals,
rejection realms and callback completion, and PageVm task-ID reuse.
Keep child document subtrees active while a history response is pending or
ignored. Check beforeunload before navigate, then defer pagehide and unload
until a document response commits. Preserve the event flag independently
of temporary native unload counters so later navigations remain usable.
Unload removed frame subtrees before retiring their Window and Document
wrappers, and reject active navigation trackers before removal events.
Dispatch in the retiring realm so removing cross-origin frames does not
leak a SecurityError into the parent.
Cover delayed responses, 204/205/download retries, stop(), and detachment
with gated protocol tests.
Route popup history traversal through the Window-owned task queue and retain
its Navigation API signal and method results until commit or cancellation.
Window.stop() aborts those API results while the physical traversal continues.
Deliver popup pageshow and traversal unload events, preserve nested unload
guards, and handle close() from navigate and pagehide callbacks. Add gated
HTTP regression coverage for traversal metadata, cancellation, ignored
responses, and opener history isolation.
Start real loads for popup Navigation API calls and reloads. Keep the
active URL and history while fetching, then install the destination
history only when its response commits, including redirects.
Cancel pending resource loaders on stop or close, preserve pending
promises for ignored responses, and reject reentrant navigations during
stop callbacks. Add gated HTTP regression tests for these boundaries.
Notify Navigation API in the popup's exact execution scope before the close
task retires its callbacks and LocalWindow. Re-establish the popup alias
from its retained Window when its opener has already been detached.
Cover precommit and committed query, fragment, and reload interceptions,
late handler settlements, reentrant close/navigation, same-name popups,
and opener retirement while checking unrelated windows remain usable.
Resolve Window.stop() through the receiver's captured Window binding and
cancel intercepted fragment/reload navigations as well as descendant
frame navigations. Preserve cross-document traversal handling and guard
ancestor stops against reentrant abort listeners. Keep Window identity
valid across document.open() without targeting replacement LocalWindows.
Import the corrected upstream stop-before-commit WPT and cover receiver,
shadow-frame, history, promise, and callback reentrancy behavior.
Reject the navigation API method's committed and finished promises before
firing navigateerror, then reject the transition promises. Apply this order
to pending precommit rejection and cancellation for navigate/reload and
history traversal, including microtasks enqueued by abort/error listeners.
Retain the traversal committed resolver across author callbacks while
deferring its rejection until the API method promises have been rejected.
Add both unmodified upstream precommit-rejection ordering variants and a
39-scenario protocol regression covering method and native navigations,
child/popup owners, rejection identity, cancellation, history, and downloads.
Keep precommit controllers usable until interception commits and read the
final redirect URL, history mode, and state after all precommit handlers
settle. Resolve redirects against the owning document base URL, including
popup documents, and expose the redirected navigation type on the event.
Route intercepted Location, anchor, and form navigations through the shared
pending precommit transaction. Reject controllers from retired windows and
prevent canceled work from committing even when the old event is edited.
Add two unmodified upstream redirect WPT variants and protocol regressions
covering async redirects, multiple handlers, cancellation, history parity,
download suppression, child windows, and popup retirement.
Run intercepted download links through the shared same-document navigation
lifecycle, including precommit handlers, redirects, cancellation, history
commits and transition settlement. Suppress the download once intercepted
and preserve the source element identity in child and popup windows.
Allow shared settlement without Navigation API method promises, resolve
transition.committed with undefined and finish fulfilled handlers in their
existing reaction so navigatesuccess precedes author microtasks.
Cover download interception and transition return values with protocol
regressions, plus four unmodified upstream WPT query variants.
Settle the canceled event's transition promises with its AbortError. Retain the committed resolver before abort/error callbacks so a reentrant navigation cannot resolve the old transition, and preserve any replacement transition during cleanup.
Cover back(), navigate(), and reload() cancellation by stop(), a subsequent navigation, and a subsequent intercepted navigation, including promise reasons and renderer/CDP history consistency.
Carry transition resolvers through pending traversal commits and settlement,
reusing precommit transitions and the shared navigation lifecycle. Keep
committed reactions after currententrychange and intercept handlers, and
finish empty handler lists asynchronously.
Preserve rejection reasons and transitions started by completion callbacks.
Add default protocol regressions and four unmodified upstream WPT variants.
Serve their .mjs helper through the compat fixture server.
Intercepted Navigation API pushes and replacements use URL/history updates.
Skip popstate and hashchange in their shared commit path, including deferred
precommit handlers and destinations that would otherwise change documents.
Import upstream precommit push, replace, reload, and traversal tests, and
cover event suppression, handler failures, state, and CDP history together.
Synchronize Document.URL and report same-document pushes, replacements, and
traversals when their renderer entries commit. Navigation API commits now
reach browser history, and reentrant currententrychange/popstate handlers
cannot reorder entries or trigger traversal URL drift assertions.
Cover mixed Navigation, History, and Location sequences through CDP,
including nested callbacks, intercepted/precommit traversals, and cancellation.
Use the shared Location history and event pipeline for committed popup
Documents. Preserve the Document and Navigation API state, clear classic
history state, and bind new entries and events to the correct Window.
Synchronize popup Document URLs without touching the opener, stop when
navigation listeners close or replace the popup, and replace same-URL entries.
Keep initial empty popups' Navigation entries disabled and preserve their
native event delivery. Cover loading phases, cancellation, and repeated URLs.
Resolve Location's Document through the shared Window owner lookup and
include popup Documents in the native completely-loaded query. Mark them
complete after load callbacks finish, preserving document.open state and
checking the exact Document owner after reentrant replacement.
Consult the incumbent Window's native transient activation in addition
to the current protocol gesture scope. Cover parser/load navigation,
post-load navigation, document.open, window.open(_self), and input-driven
activation. Refresh the observed Location WPT case statuses.
The scripted_click_assign_during_load WPT now passes. Its assign() sibling
expects a separate push rule, but current HTML routes both APIs through
Location-object navigate; Chrome 145 also fails that older expectation.
Record both observed results in the case lists.
Resolve popup owners through the Window execution-context registry and
compile content attributes with the popup Window, Document, form, and
element scopes. Capture the popup owner when registering callbacks so
tasks retire with the popup even when compilation starts in the opener.
Route compile errors to the popup and preserve handler replacements made
while reporting them. Cover scope lookup, cancellation, lazy compile
errors, reentry, and timer retirement; refresh the observed WPT results.
Install the native LegacyUnforgeable getter/setter when creating detached
Document projections instead of defining a readonly null data property.
This lets popup Window initialization supply the actual Location while
windowless and retired Documents continue to return null.
Validate the Document brand before reading or forwarding the Location.
Cover descriptor shape, incompatible receivers, popup navigation, and
retained Documents after popup closure.
HTML crashtests were classified as testharness pages and timed out waiting
for callbacks they never emit. Recognize WPT crash filenames/directories,
route them through CDP, and wait for load, fonts, animation frames, and
test-wait removal. Observe renderer crash events while awaiting commands
and preserve timeouts without inventing subtests.
Cover classification, navigation identity, readiness, crash, timeout, and
recovery behavior. Record 29 newly verified passes. The related 49-case
Location regression remains green; one unload crashtest times out in both
Chrome and Moli and remains unresolved.
Check the relevant Document lifetime after argument conversion and before
parsing or navigating. Inactive Location objects expose about:blank while
retained Documents keep their URLs. Track the actual Window owner so old
Locations cannot navigate a replacement iframe Window or document.
Cover removal, reinsertion, navigation, srcdoc, closed popups, conversion
side effects, and receiver validation. Update the retained child Window
expectation and record the no-browsing-context WPT pass.
Keep each live window's Location identity while rechecking protected access and cached members against Window origin policy. Use native receiver brands and caller-realm cross-origin descriptors while preserving href and replace navigation.
Cover both document.domain transition directions, cross-origin reflection and native Proxy identity. Record five newly passing WPT pages.
Validation: cargo fmt, strict workspace clippy, and full nextest (19,506 passed; 13 skipped). Related WPT: 48/50 passed, with the remaining failure and timeout unchanged from baseline.
Use the shared source executor for written main-document scripts so syntax and runtime exceptions reach their Window without escaping to the writer. Preserve script provenance, cleanup, and load events for fetched classic scripts after execution errors.
Add four main/child parser regressions. Verified with fmt, strict workspace Clippy, 19478 passing nextest tests, 84 Chromium comparison checks, and 62 WPT pages without new failures.
Keep blocked writes with the input position saved by each parser script. Share the context between main and child parsers so external-script suspension preserves nested caller tails and consecutive write order.
Add four integration regressions across main/child and navigation/script-created parsers. Validated with fmt, strict workspace Clippy, 19474 passing nextest tests, 18 Chromium comparison checks, and 50 WPT pages without new failures.
Use the realm Document prototype bindings instead of frame-captured own
methods, so borrowed calls and retained Documents select their own parser.
Validate native receivers before conversion and use the receiver global for
Trusted Types requirements and default policies.
Clear listeners through actual parent and shadow-host relationships when
replacing a retired document tree, preserving listeners outside that tree.
Validation: cargo fmt --all; strict all-feature, all-target workspace Clippy;
cargo nextest run --no-fail-fast (19,470 passed, 13 skipped); 392 fixture
tests; 179/179 cross-engine probe checks. The active.window.js WPT improves
from 4/7 to 7/7 with no new failures across the comparison set.