Commit Graph
1689 Commits
Author SHA1 Message Date
ldm0 fbbfcd18f0 fix(history): preserve forward entries on cross-document replacement 2026-09-23 00:14:10 +08:00
ldm0 8d02c41333 fix(history): use committed child URLs for navigation referrers 2026-09-23 00:14:10 +08:00
ldm0 fbb2ae0957 fix(script): report dynamic inline errors in the document realm
Run main-document dynamic inline scripts through the shared classic-script
executor in the document's main world. Keep currentScript set while parse and
runtime exceptions are synchronously reported, then restore the outer script
without propagating the exception through the inserting DOM operation.

Cover nested error handlers, thrown object identity,
re-insertion, shadow trees, borrowed child-realm insertion methods, isolated
worlds, and deferred microtasks. Remove the redundant inline load-event
scheduling entry point.
2026-09-23 00:14:10 +08:00
ldm0 7870351fea fix(location): forward assignments through href setters
Implement Window and Document location PutForwards by retrieving the
receiver's Location and assigning the original value to href. This keeps
conversion, exceptions, and navigation in the target href setter's realm
and preserves null and undefined as URL inputs. Remove the Location attribute
conversion helper's nullish-to-empty shortcut so href receives their string values.

Use the native Document brand for both own location accessors, reject
windowless null Locations before conversion, and keep constructed Document
setters on the same forwarding path. Share native cross-origin Location
assignment between Proxy calls and PutForwards so nested native setters keep
their current realm instead of the incumbent author script realm.

Cover borrowed setters and getters across three realms, forged and Proxy
receivers, conversion order, intrinsic error constructors, and nullish URL
navigation. The official cross-realm Location WPT improves from 9/11 to
10/11; the remaining cross-origin Window invalid-receiver failure is
unchanged.
2026-09-23 00:14:10 +08:00
ldm0 ba3a2e5425 fix(window): reject Promise method receiver errors
Use the existing returns_promise binding adapter for fetch and createImageBitmap.
Check native Window branding and same-origin access before argument conversion,
then reject invocation errors with intrinsic Promises in the function realm.
Keep Fetch's captured Window binding across observable conversions. Recognize
retained native globals and their registry retirement before private-slot reads
so detached callbacks preserve their shutdown rejection. Skip unhandled-rejection
notifications in retired native contexts before reading global scope markers.

Cover cross-realm and discarded receivers, registered native Window wrappers,
author Proxies, constructor tampering, and conversion exception identity.
Update the cross-origin Fetch regression to the Web IDL/WPT rejection contract.
2026-09-23 00:14:10 +08:00
ldm0 262d3d6a4c fix(window): validate synchronous method receivers
Check native Window receivers and same-origin access before argument conversion
in synchronous methods. Report operation receiver errors in the callee realm,
while retaining captured Window ownership and registered native wrappers.

Keep Worker base64 operations on their shared conversion path. Cover forged and
author Proxy receivers, borrowed calls, conversion ordering, cross-realm errors,
Worker base64 behavior, and EventTarget methods on genuine Nodes.
2026-09-23 00:14:10 +08:00
ldm0 9bb0712cfe fix(window): validate scheduling method receivers
Use the shared native Window and same-origin receiver check before timer, animation, idle, and microtask methods convert arguments or queue work. Reject foreign Windows and forged receivers in the callee realm while preserving genuine borrowed calls and native bridge wrappers.

Cover all nine methods across parent/child realms, conversion ordering, author Proxies, nullish defaults, and discarded foreign Windows. Keep Worker callbacks and task lifetime handling intact.

Validation: cargo fmt --all; strict workspace/all-targets/all-features Clippy; full nextest 19586 passed, 13 skipped; focused 1357 passed; 863 browser checks agree with Chromium. Official cross-origin WPT remains 78/90 with its first restricted-method failure advancing to getComputedStyle; 14 control pages are unchanged.
2026-09-23 00:14:10 +08:00
ldm0 bc7c32ba8c fix(window): enforce origin checks on restricted accessors
Use native Window receiver and same-origin checks before reading protected
attributes, replacing properties, converting strings, or creating storage
and Trusted Types objects. Share event and viewport getter callbacks across
runtime and template bindings. Materialize caches in the receiver realm and
stop name mutations when string conversion throws.

Cover cross-realm exception constructors, author Proxies and forged
receivers, replaceable attributes, and nested current-event restoration.
2026-09-23 00:14:10 +08:00
ldm0 1a556773ba fix(window): support borrowed cross-origin getters
Read permitted Window getters through the native cross-origin surface,
preserving Window and Location identity across navigation and disposal.
Share alias callbacks between runtime and template initialization, and
apply native brand and same-origin checks to protected Window accessors.

Cover cross-realm receivers, forged objects and author Proxies, author
property replacements, location conversion, and iframe lifecycle in a
391-check regression fixture.
2026-09-23 00:14:10 +08:00
ldm0 3c7d9ecb6a fix(window): validate event handler receivers with native brands
Share Window brand and same-origin checks across event accessors and frameElement.
Honor LegacyLenientThis for mouseenter/mouseleave without suppressing cross-origin
SecurityErrors, and preserve errors in the accessor realm.

Recognize native bridge and popup Window wrappers through their existing Web IDL
brand. Copying __moliNativeBridge or wrapping a Window in an author Proxy must not
validate a receiver or mutate the Window's handlers.

Add a reusable browser regression for 868 assertions covering receiver identity,
handler ownership, realm errors, author traps, and navigation, plus a native
Window wrapper regression.

Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast: 19,582 passed, 13 skipped
- Focused workspace tests: 1,048 passed
- Browser regression: 868/868 in Moli and Chromium; native Window wrapper probe passed
- Unmodified cross-origin-objects WPT: 75/90 -> 78/90; exactly the three
  LegacyLenientThis failures removed, with 12 existing failures unchanged
- Eight surrounding WPT controls unchanged
2026-09-23 00:14:10 +08:00
ldm0 37a7449100 fix(window): apply cross-origin Symbol fallback values
CrossOriginPropertyFallback requires undefined for Symbol.toStringTag as well
as Symbol.hasInstance and Symbol.isConcatSpreadable. Use that common value in
every cross-origin Window/Location surface instead of exposing interface tags.
Same-origin objects retain their normal Window and Location tags.

Cover fallback reads, descriptors, presence, mutation rejection, caller realms,
origin transitions, retained Location objects, and removed Windows. Update the
older migration test to expect the cross-origin Object class string.

Validation: cargo fmt --all; strict workspace Clippy with all targets/features;
cargo nextest run --no-fail-fast. All 232 browser regression checks pass. The
official cross-origin-objects.html improves from 69/90 to 75/90, with the other
15 failures unchanged; eight WPT control pages retain their baseline results.
2026-09-23 00:14:10 +08:00
ldm0 57232b034a fix(iframe): reload unchanged src during load callbacks
Repeated src assignments must schedule navigation even from the child Window
or iframe element load handler. The old early return left the WPT cross-origin
object test waiting forever on the final frame in its reload barrier. Remove
the load-dispatch tracking and URL helpers used only by that guard.

Cover property and setAttribute writes, same-origin and cross-origin owner
loads, and child Window loads. Check asynchronous navigation, fresh Documents,
stable WindowProxy identity, and loaded descendants across three reloads.

Validation: cargo fmt --all; strict workspace Clippy with all targets/features;
cargo nextest run --no-fail-fast. All 84 browser regression assertions pass in
Moli and Chromium. The unmodified cross-origin-objects.html completes all 90
subtests (69 pass, 21 fail); the same 21 failures reproduce on the old binary
when test reload calls are diagnostically deferred. Eight WPT control pages
retain exactly their baseline results.
2026-09-23 00:14:10 +08:00
ldm0 c33ebfa615 fix(window): follow child target-name visibility
Select the first direct child with each target name before checking its
original origin against the receiving Window. Share this lookup between
same-origin and cross-origin named access, including live name changes and
navigation, without applying document.domain relaxation.

Allow named children to shadow non-exposed properties and the then fallback,
while keeping cross-origin IDL properties first. Use canonical array-index
parsing so names such as 01 and 4294967295 remain available by name.

Cover property descriptors, duplicate names, origin changes, renaming,
removal, and indexed WindowProxy identities. The named-access WPT now passes
all three subtests. An older frameElement WPT assumes that cross-origin
name-only lookup succeeds, contrary to this requirement; direct and indexed
frameElement security checks remain covered separately.
2026-09-23 00:14:10 +08:00
ldm0 108706d3d0 fix(window): expose live cross-origin child windows
Use the native top WindowProxy for cross-origin parent/top references and
resolve indexed and named children from the live browsing context. Preserve
window identities through child navigation and document.domain changes,
with SecurityError for inaccessible or missing properties.

Create exposed methods and getters in the accessing realm. Weakly cache
these surfaces while retained functions trace their shared callback data,
preserving identity across garbage collection without rooting dead realms.

Cover top and nested parents, append/remove/navigation, borrowed postMessage,
function realms and caching, and document.domain transitions.
2026-09-23 00:14:10 +08:00
ldm0 d60a7f624c fix(window): enforce frameElement origin checks 2026-09-23 00:14:10 +08:00
ldm0 d948520501 fix(window): retain cross-origin access after frame removal
Keep cross-origin access surfaces on their owning Window globals with weak
native lookups, so retained references remain readable after retirement.
Validate the original proxy and realm before resolving child state, and prevent
old postMessage and Location receivers from targeting a reinserted iframe.
Keep current isolated-world globals valid through their native Window identity.

Add shared browser and Rust regression coverage for direct, ancestor, and
replaceChildren removal in ordinary and closed shadow trees.
2026-09-23 00:14:10 +08:00
ldm0 b09dad8e5d fix(window): preserve frame relationships until unload finishes
Check the captured LocalWindow identity when reading parent, top, frameElement
and closed. DOM removal disconnects the container before its unload callbacks
run, while native ownership remains current until the callbacks finish.

Include shadow trees when collecting browsing contexts from disconnected
subtrees so removing a shadow host unloads and retires its frames as well.
Cover four removal operations in light and closed shadow trees, callback
visibility and Window relationships, and retained references after reattachment.
2026-09-23 00:14:10 +08:00
ldm0 3a343fa808 fix(navigation): preserve queued traversal targets and results
Reject retained traversal results in their original realm when the target
LocalWindow retires before the history task runs. Complete the Promise
reactions without firing navigation events or applying stale history.
Keep PageVm namespaces and exact task ownership checks when consuming the
payload, and leave classic History tasks without results as no-op cleanup.

Choose back/forward destinations from the committed current entry so
repeated pending calls share the same destination and result Promises.
Cover removed and reinserted frames, same- and cross-document traversals,
rejection realms and callback completion, and PageVm task-ID reuse.
2026-09-23 00:14:10 +08:00
ldm0 44e019b99e fix(navigation): preserve iframe lifecycle during history traversal
Keep child document subtrees active while a history response is pending or
ignored. Check beforeunload before navigate, then defer pagehide and unload
until a document response commits. Preserve the event flag independently
of temporary native unload counters so later navigations remain usable.

Unload removed frame subtrees before retiring their Window and Document
wrappers, and reject active navigation trackers before removal events.
Dispatch in the retiring realm so removing cross-origin frames does not
leak a SecurityError into the parent.
Cover delayed responses, 204/205/download retries, stop(), and detachment
with gated protocol tests.
2026-09-23 00:14:10 +08:00
ldm0 1448450d84 test(wpt): support programmed history traversal responses 2026-09-23 00:14:10 +08:00
ldm0 f31b43920b fix(navigation): dispatch popup cross-document history events
Route popup history traversal through the Window-owned task queue and retain
its Navigation API signal and method results until commit or cancellation.
Window.stop() aborts those API results while the physical traversal continues.

Deliver popup pageshow and traversal unload events, preserve nested unload
guards, and handle close() from navigate and pagehide callbacks. Add gated
HTTP regression coverage for traversal metadata, cancellation, ignored
responses, and opener history isolation.
2026-09-23 00:14:10 +08:00
ldm0 f8b299d567 fix(navigation): track and cancel popup document requests
Start real loads for popup Navigation API calls and reloads. Keep the
active URL and history while fetching, then install the destination
history only when its response commits, including redirects.

Cancel pending resource loaders on stop or close, preserve pending
promises for ignored responses, and reject reentrant navigations during
stop callbacks. Add gated HTTP regression tests for these boundaries.
2026-09-23 00:14:09 +08:00
ldm0 310b594acf fix(navigation): abort popup navigations before closing
Notify Navigation API in the popup's exact execution scope before the close
task retires its callbacks and LocalWindow. Re-establish the popup alias
from its retained Window when its opener has already been detached.

Cover precommit and committed query, fragment, and reload interceptions,
late handler settlements, reentrant close/navigation, same-name popups,
and opener retirement while checking unrelated windows remain usable.
2026-09-23 00:14:09 +08:00
ldm0 c6f858b39d fix(navigation): cancel stopped window subtrees
Resolve Window.stop() through the receiver's captured Window binding and
cancel intercepted fragment/reload navigations as well as descendant
frame navigations. Preserve cross-document traversal handling and guard
ancestor stops against reentrant abort listeners. Keep Window identity
valid across document.open() without targeting replacement LocalWindows.

Import the corrected upstream stop-before-commit WPT and cover receiver,
shadow-frame, history, promise, and callback reentrancy behavior.
2026-09-23 00:14:09 +08:00
ldm0 545299b648 test(wpt): support DOMException assertion constructors 2026-09-23 00:14:09 +08:00
ldm0 79c4ce46e4 fix(navigation): order precommit rejection promises
Reject the navigation API method's committed and finished promises before
firing navigateerror, then reject the transition promises. Apply this order
to pending precommit rejection and cancellation for navigate/reload and
history traversal, including microtasks enqueued by abort/error listeners.

Retain the traversal committed resolver across author callbacks while
deferring its rejection until the API method promises have been rejected.

Add both unmodified upstream precommit-rejection ordering variants and a
39-scenario protocol regression covering method and native navigations,
child/popup owners, rejection identity, cancellation, history, and downloads.
2026-09-23 00:14:09 +08:00
ldm0 ec11a61fbd fix(navigation): preserve asynchronous precommit redirects
Keep precommit controllers usable until interception commits and read the
final redirect URL, history mode, and state after all precommit handlers
settle. Resolve redirects against the owning document base URL, including
popup documents, and expose the redirected navigation type on the event.

Route intercepted Location, anchor, and form navigations through the shared
pending precommit transaction. Reject controllers from retired windows and
prevent canceled work from committing even when the old event is edited.

Add two unmodified upstream redirect WPT variants and protocol regressions
covering async redirects, multiple handlers, cancellation, history parity,
download suppression, child windows, and popup retirement.
2026-09-23 00:14:09 +08:00
ldm0 c58738585d fix(navigation): complete intercepted download transitions
Run intercepted download links through the shared same-document navigation
lifecycle, including precommit handlers, redirects, cancellation, history
commits and transition settlement. Suppress the download once intercepted
and preserve the source element identity in child and popup windows.

Allow shared settlement without Navigation API method promises, resolve
transition.committed with undefined and finish fulfilled handlers in their
existing reaction so navigatesuccess precedes author microtasks.

Cover download interception and transition return values with protocol
regressions, plus four unmodified upstream WPT query variants.
2026-09-23 00:14:09 +08:00
ldm0 a74a31a097 fix(navigation): reject transitions canceled during precommit
Settle the canceled event's transition promises with its AbortError. Retain the committed resolver before abort/error callbacks so a reentrant navigation cannot resolve the old transition, and preserve any replacement transition during cleanup.

Cover back(), navigate(), and reload() cancellation by stop(), a subsequent navigation, and a subsequent intercepted navigation, including promise reasons and renderer/CDP history consistency.
2026-09-23 00:14:09 +08:00
ldm0 65454471de fix(navigation): track intercepted traversal transitions
Carry transition resolvers through pending traversal commits and settlement,
reusing precommit transitions and the shared navigation lifecycle. Keep
committed reactions after currententrychange and intercept handlers, and
finish empty handler lists asynchronously.

Preserve rejection reasons and transitions started by completion callbacks.
Add default protocol regressions and four unmodified upstream WPT variants.
Serve their .mjs helper through the compat fixture server.
2026-09-23 00:14:09 +08:00
ldm0 1261ce9ed2 fix(navigation): suppress fragment events for intercepted commits
Intercepted Navigation API pushes and replacements use URL/history updates.
Skip popstate and hashchange in their shared commit path, including deferred
precommit handlers and destinations that would otherwise change documents.

Import upstream precommit push, replace, reload, and traversal tests, and
cover event suppression, handler failures, state, and CDP history together.
2026-09-23 00:14:09 +08:00
ldm0 b85b7263b4 fix(history): publish same-document commits before callbacks
Synchronize Document.URL and report same-document pushes, replacements, and
traversals when their renderer entries commit. Navigation API commits now
reach browser history, and reentrant currententrychange/popstate handlers
cannot reorder entries or trigger traversal URL drift assertions.

Cover mixed Navigation, History, and Location sequences through CDP,
including nested callbacks, intercepted/precommit traversals, and cancellation.
2026-09-23 00:14:09 +08:00
ldm0 cb05f99981 fix(history): commit popup fragments through shared navigation
Use the shared Location history and event pipeline for committed popup
Documents. Preserve the Document and Navigation API state, clear classic
history state, and bind new entries and events to the correct Window.

Synchronize popup Document URLs without touching the opener, stop when
navigation listeners close or replace the popup, and replace same-URL entries.
Keep initial empty popups' Navigation entries disabled and preserve their
native event delivery. Cover loading phases, cancellation, and repeated URLs.
2026-09-23 00:14:09 +08:00
ldm0 b31bd71d1e fix(history): replace Location entries until popup load completes
Resolve Location's Document through the shared Window owner lookup and
include popup Documents in the native completely-loaded query. Mark them
complete after load callbacks finish, preserving document.open state and
checking the exact Document owner after reentrant replacement.

Consult the incumbent Window's native transient activation in addition
to the current protocol gesture scope. Cover parser/load navigation,
post-load navigation, document.open, window.open(_self), and input-driven
activation. Refresh the observed Location WPT case statuses.

The scripted_click_assign_during_load WPT now passes. Its assign() sibling
expects a separate push rule, but current HTML routes both APIs through
Location-object navigate; Chrome 145 also fails that older expectation.
Record both observed results in the case lists.
2026-09-23 00:14:09 +08:00
ldm0 7d64c21b45 fix(events): compile popup content handlers in their owner scope
Resolve popup owners through the Window execution-context registry and
compile content attributes with the popup Window, Document, form, and
element scopes. Capture the popup owner when registering callbacks so
tasks retire with the popup even when compilation starts in the opener.

Route compile errors to the popup and preserve handler replacements made
while reporting them. Cover scope lookup, cancellation, lazy compile
errors, reentry, and timer retirement; refresh the observed WPT results.
2026-09-23 00:14:09 +08:00
ldm0 d9584d90a2 fix(dom): preserve Location accessors on popup Documents
Install the native LegacyUnforgeable getter/setter when creating detached
Document projections instead of defining a readonly null data property.
This lets popup Window initialization supply the actual Location while
windowless and retired Documents continue to return null.

Validate the Document brand before reading or forwarding the Location.
Cover descriptor shape, incompatible receivers, popup navigation, and
retained Documents after popup closure.
2026-09-23 00:14:09 +08:00
ldm0 e19d27182c fix(wpt): allow Chrome test popups without user activation 2026-09-23 00:14:09 +08:00
ldm0 1d4a128b46 fix(wpt): execute crashtests with their readiness protocol
HTML crashtests were classified as testharness pages and timed out waiting
for callbacks they never emit. Recognize WPT crash filenames/directories,
route them through CDP, and wait for load, fonts, animation frames, and
test-wait removal. Observe renderer crash events while awaiting commands
and preserve timeouts without inventing subtests.

Cover classification, navigation identity, readiness, crash, timeout, and
recovery behavior. Record 29 newly verified passes. The related 49-case
Location regression remains green; one unload crashtest times out in both
Chrome and Moli and remains unresolved.
2026-09-23 00:14:09 +08:00
ldm0 0ea09e300c fix(runtime): stop navigation through inactive Location objects
Check the relevant Document lifetime after argument conversion and before
parsing or navigating. Inactive Location objects expose about:blank while
retained Documents keep their URLs. Track the actual Window owner so old
Locations cannot navigate a replacement iframe Window or document.

Cover removal, reinsertion, navigation, srcdoc, closed popups, conversion
side effects, and receiver validation. Update the retained child Window
expectation and record the no-browsing-context WPT pass.
2026-09-23 00:14:09 +08:00
ldm0 dc79c48c14 fix(runtime): recheck retained Location origin-domain access
Keep each live window's Location identity while rechecking protected access and cached members against Window origin policy. Use native receiver brands and caller-realm cross-origin descriptors while preserving href and replace navigation.

Cover both document.domain transition directions, cross-origin reflection and native Proxy identity. Record five newly passing WPT pages.

Validation: cargo fmt, strict workspace clippy, and full nextest (19,506 passed; 13 skipped). Related WPT: 48/50 passed, with the remaining failure and timeout unchanged from baseline.
2026-09-23 00:14:09 +08:00
ldm0 719a23dc88 test(webidl): honor lenient readystatechange receivers 2026-09-23 00:14:09 +08:00
ldm0 ebfd18c710 fix(runtime): preserve origin-domain access for retired windows 2026-09-23 00:14:09 +08:00
ldm0 ea2c873cb0 fix(dom): clear defaultView after browsing context destruction 2026-09-23 00:14:09 +08:00
ldm0 347f1546f9 fix(runtime): preserve retained child Window globals 2026-09-23 00:14:09 +08:00
ldm0 6f3fdb80d4 fix(dom): update document.open URLs from the entry document 2026-09-23 00:14:09 +08:00
ldm0 51455017c5 fix(parser): respect script nesting for stylesheet waits 2026-09-23 00:14:09 +08:00
ldm0 91368fe52f fix(runtime): admit document lifecycle during awaited evaluation 2026-09-23 00:14:09 +08:00
ldm0 d84059e00c fix(script): report document.write script exceptions
Use the shared source executor for written main-document scripts so syntax and runtime exceptions reach their Window without escaping to the writer. Preserve script provenance, cleanup, and load events for fetched classic scripts after execution errors.

Add four main/child parser regressions. Verified with fmt, strict workspace Clippy, 19478 passing nextest tests, 84 Chromium comparison checks, and 62 WPT pages without new failures.
2026-09-23 00:14:09 +08:00
ldm0 a8955e6ea1 fix(parser): preserve nested document.write insertion points
Keep blocked writes with the input position saved by each parser script. Share the context between main and child parsers so external-script suspension preserves nested caller tails and consecutive write order.

Add four integration regressions across main/child and navigation/script-created parsers. Validated with fmt, strict workspace Clippy, 19474 passing nextest tests, 18 Chromium comparison checks, and 50 WPT pages without new failures.
2026-09-23 00:14:09 +08:00
ldm0 d341b0b48d fix(dom): dispatch document streams by their receiver
Use the realm Document prototype bindings instead of frame-captured own
methods, so borrowed calls and retained Documents select their own parser.
Validate native receivers before conversion and use the receiver global for
Trusted Types requirements and default policies.

Clear listeners through actual parent and shadow-host relationships when
replacing a retired document tree, preserving listeners outside that tree.

Validation: cargo fmt --all; strict all-feature, all-target workspace Clippy;
cargo nextest run --no-fail-fast (19,470 passed, 13 skipped); 392 fixture
tests; 179/179 cross-engine probe checks. The active.window.js WPT improves
from 4/7 to 7/7 with no new failures across the comparison set.
2026-09-23 00:14:09 +08:00