Skip to content

[Epic] Qualify unchanged Code OSS webviews and nested document contexts #264

Description

@wieslawsoltes

Exact merged-head diagnostic checkpoint — 21 September 2026

Unchanged Code OSS 645f29cc is pinned locally with merged WebScene 5b4739c8 (native stack #902, focused PRs #899–#901 merged) and merged AppScene 36d7a82e (focused PR #403 merged). The demo branch is clean at local commit 074d2cbe, unpushed, with Actions disabled. No focused PRs remain open; keep WebScene consolidation #76, AppScene consolidation #65 and vscode-demo integration #1 open/unmerged.

A clean 2,909-file SDK from those exact heads passed native CTest, macOS runtime profile, installed CLI verification and release preflight. The CLI published a signed 709 MiB local diagnostic Release at vscode-demo/dist/appscene-release-36d7a82-5b4739c8-markdown/Code OSS AppScene.app; strict codesign and the installed-resource callback contract pass. Native computer input opened real remote beta/README.md and five Explorer rows. A Markdown Preview editor then appeared with a blank white pane; the current trace does not isolate the next nested resource/message failure, and the shortcut sequence also pasted clipboard text into the fixture editor. This is not a qualified full release. AppScene #402/#398 and WebScene #264/#267 stay open.

Resume with controlled native Preview invocation and nested resource/worker/message tracing; require actual painted Markdown, Chromium-matched geometry, security, lifecycle and performance. Then continue Explorer first-child paint #252/#243 and AppScene picker #131, remote Save As/recovery #269, terminal #244, CSS #235, accessibility/Chat, Linux/Windows WPT, bundle-size and release-wide CI gates. The authored open-issue inventory and exact local evidence are in vscode-demo/docs/open-issue-plan.md and docs/validation/markdown-preview-prelude-080ee9c-20260921.md. No Electron/CEF shell or Code OSS source rewrite was introduced.

Parent epic: #227

Outcome

Run the unchanged VS Code OSS 1.137 webview stack in WebScene with browser-shaped isolation, resource delivery, interaction, lifecycle, visual, performance, and accessibility behavior. Markdown Preview is the first deterministic reproduction, not the boundary of the work.

Pinned audit baseline: AppScene 9f434e0, WebScene b81f594c, VS Code OSS 645f29c.

Unchanged consumers in scope

  • extension API webview panels, webview views, custom editors, and editor insets;
  • Markdown Preview and Markdown editor, Mermaid editor, and Simple Browser;
  • notebook back-layer/output webviews and notebook diff/output editors;
  • release notes, Getting Started, extension details, image carousel, and contributed panels;
  • chat tool output, agent-plugin editor, MCP app content, and Copilot suggestion panels.

They all converge on webviewElement.ts and browser/pre/index.html; success from a hand-authored iframe does not qualify this epic.

Proven dependency chain

  1. Expose HTMLIFrameElement.sandbox for Code OSS webviews and Markdown Preview #253: HTMLIFrameElement.sandbox.add(...) currently throws synchronously.
  2. Complete ServiceWorker control and client lifecycle for Code OSS webviews #265 service-worker control plane: Markdown does not set disableServiceWorker; index.html rejects when navigator.serviceWorker is absent.
  3. Stream and cache admitted Code OSS webview resources #266 service-worker resource plane: service-worker.js needs FetchEvent, Clients, CacheStorage, readable/writable/transform streams, ranges, cache validation, and resource-message transfer.
  4. Enforce secure nested-document lifecycle for Code OSS webviews #267 secure nested-document lifecycle: the outer frame loads the prelude, then creates fake.html, accesses contentWindow/contentDocument, and uses open/write/close to install extension HTML under CSP and sandbox rules.
  5. Complete nested-webview interaction, find, focus, and accessibility handoff #268 messaging and interaction: Implement Worker, transferable MessagePort, and iframe contexts for Code OSS #81 owns transferable MessagePort/worker completion; the webview prelude also needs focus/input/clipboard/find/selection/context-menu/drag/link/download/reload behavior.
  6. Release-wide acceptance is owned by Establish Chromium/AppScene visual and geometry regression gates for unchanged Code OSS #259 (visual/geometry), Qualify all unchanged Code OSS workbench commands, panels, and feature lifecycles #260 (workbench consumers), Qualify Code OSS Chat and auxiliary-bar interaction, streaming, and lifecycle #261 (Chat), Qualify Code OSS accessibility semantics, keyboard navigation, and native exposure #262 (accessibility), Publish a Code OSS Web API capability ledger and expand WPT coverage #263 (Web API/WPT ledger), and AppScene#130 (installed release). This epic supplies their nested-document lane rather than duplicating those tickets.

Related cross-repository owners are AppScene#27 (input/focus), #30 (native accessibility), #31 (packaged URLs/origins), #32 (downloads/clipboard/drag), #34 (network/streams), #36 (workers/messaging), and #41 (embedded document contexts). WebScene #81 and #102 remain shared prerequisites. CSS/visual issues remain under #235 and open PR #245 is outside this stack.

Native subissues

Global gates

  • Use selected upstream WPTs plus a checked-in Chromium oracle for each standards surface; document exclusions instead of silently skipping.
  • Exercise top-level and nested realms on macOS arm64, Linux x64, and Windows x64 native runners and installed-package consumers.
  • Enforce CSP, opaque/same-origin sandbox transitions, local-resource roots, MIME/range/cache headers, navigation admission, and stale-generation rejection. No permissive bypass qualifies.
  • At steady state, 100 create/update/find/reload/dispose cycles leave zero live iframe realms, workers, clients, ports, observers, streams, cached response leases, and pending host requests from the disposed generation. After warm-up, retained RSS growth must be <= 8 MiB for the deterministic fixture and no queue may exceed its documented cap.
  • For the exact vscode-demo/README.md, cold command-to-first-complete-scene p95 must be <= 2 s and warm edit-to-updated-scene p95 <= 250 ms on the recorded macOS reference machine; each focused issue has tighter component budgets. Publish Chromium and native timings rather than hiding a regression inside the end-to-end allowance.
  • Chromium/native comparisons cover geometry, scroll, theme, local/external resources, images, focus order, links, find highlights, and the semantic accessibility tree. AppScene#30 owns native platform exposure.

Proposed PR stacks and schedule

Stack A — synchronous frame creation

  1. Expose HTMLIFrameElement.sandbox for Code OSS webviews and Markdown Preview #253 IDL/DOMTokenList shape;
  2. Expose HTMLIFrameElement.sandbox for Code OSS webviews and Markdown Preview #253 sandbox enforcement/navigation/teardown;
  3. Expose HTMLIFrameElement.sandbox for Code OSS webviews and Markdown Preview #253 WPT, browser oracle, native package smoke.

Stack B — service worker and resources (#265 then #266)

  1. registration/container/worker lifecycle and Clients;
  2. FetchEvent dispatch and controlled-client routing;
  3. streams and CacheStorage;
  4. VS Code resource broker, range/cache/security/performance acceptance.

Stack C — nested document and interaction (#267 then #268)

  1. src/srcdoc/fake-document navigation and realm isolation;
  2. CSP/origin/Permissions Policy enforcement;
  3. document replacement, event/focus/find/link/reload behavior;
  4. lifecycle, accessibility, and bounded stress gates.

Stack D — product qualification (#259–#263 and AppScene#130)

  1. Markdown Preview with the exact current demo README plus deterministic local/external image fixtures;
  2. notebooks/custom editors/webview views and panels;
  3. release notes/Getting Started/extension/image surfaces;
  4. chat/MCP/Mermaid/Simple Browser and final three-RID package matrix.

Stack A is first because it is the current synchronous failure. Stack B follows because the unchanged prelude cannot initialize without it. Stack C may develop behind stable A/B interfaces, but security enforcement must land before product acceptance. Stack D closes only from a cumulative exact-head package. Each stack should use focused PRs, validate its cumulative top, and merge atomically. No implementation PR belongs in this investigation phase.

Acceptance

  • Every child issue is closed with WPT/browser/native/product evidence and numeric performance/teardown results.
  • All listed unchanged webview consumers either pass or have a specific, fail-closed exclusion with an owning issue.
  • The exact pinned package completes Markdown preview and representative non-Markdown consumers without VS Code source changes, Electron, CEF, or an embedded browser.
  • Security, accessibility, lifecycle, and resource gates run in release CI rather than remaining manual claims.

Active status — 17 September 2026

#253 is complete. #276/#278 merged at 053a5627/aa786c0e; an exact stamped Code 645f29c run reaches the version-6 controller and logs webview ready after 2.665 s. #281 remains open and blocked by active MessagePort lifetime #288 in PR #245. Hold #266 until #281 rebases, passes the cumulative ServiceWorker/WebSocket gates, and merges. Full Markdown remains blank because #266 still lacks Streams, FetchEvent.respondWith, and CacheStorage resource delivery.

Current webview checkpoint — 19 September 2026

Focused children under #268 now cover nested pointer, keyboard/focus, context menus, links, downloads, inbound drag routing, and bounded outbound drag requests through WebScene 2b64b08. Semantic snapshot/action/live/delta providers are also merged for nested accessibility.

AppScene has all three inbound drag adapters plus macOS and Windows outbound consumers through f3fd2d2e. Linux Wayland/X11 outbound consumption is active under AppScene #187. macOS semantic snapshot/delta peers and the reusable Windows UIA adapter are merged; Linux AT-SPI and action/live delivery are active under AppScene #184/#185.

Remaining work is real platform host wiring and cumulative unchanged Markdown/notebook/custom-editor/extension/Chat/Simple Browser selection/find/clipboard/accessibility/navigation/reload/teardown/package acceptance. Only source diff checks ran in the newest wave.

Activity

  1. wieslawsoltes commented on Sep 17, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Stack B update: controlled Service Worker resource routing is now cumulative on main at d7720a63.

    The dependency chain now continues with #266. #267 and #268 remain downstream of its resource-plane completion.

  2. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Navigation boundary coordination: #270 requalification is complete on current main via merged test-only PR #352 (cc18b9337374ea6aadc570280d503547f3621497). The production top-level Location/native admission implementation remains sufficient; the reopened failure was a stale IndexedDB fixture that attempted script navigation without a host callback. Chromium href/replace controls, native typed-request ordering/performance, realm replacement, close lifecycle, and IndexedDB gates passed. This does not change or widen the nested-document/webview scope owned here.

  3. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    #312 is complete via #354 at 15d55a4c07d742fc3ba5f4290dfa87b082a04b70. Requalification showed the reopened Linux timeout came from a reentrant synchronous frame-writing fixture, not production ServiceWorker interception. The corrected navigated-frame retirement path passed exact-head Linux/macOS CI, portable V8, Native Linux document/SDK contracts, and 20×100 local lifecycle cycles with flat V8 heap and <=62.05 MiB RSS growth. Child portability issue #355 is also closed.

  4. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Owned from exact post-#354 main 15d55a4c07d742fc3ba5f4290dfa87b082a04b70 on feature/local-resource-admission-266.

    The first unsupported/unquealified unchanged-Code resource semantic is host-owned localResourceRoots admission. The current native runtime already contains #323 range/cache metadata, #333 bounded host-message streaming, #341 abort/timeout retirement, and #354's parser lifecycle fixture correction. This slice will preserve 401/404 admission results and fail-closed malformed/traversal behavior through that existing browser pipeline. It will not add filesystem authority or interpret WebScene's single component resource_root as a webview allowlist.

    Planned owned paths are the Service Worker resource contract/native gate and a new dedicated WebPlatformSubset admission profile. Runtime files will change only if the reduced exact-worker contract proves a missing generic Fetch/Response/stream/cache semantic.

    Collision audit: open PR #76 owns only docs/code-oss-compatibility.md; active #248 owns File System Access runtime/ABI/broker paths; #362 owns webscene_stylesheet_cssom_compatibility.h, browser DOM CSSOM tests, and its MediaList contract/profile. This slice excludes all of those, AppScene, CSS parsing/cascade, localhost mapping, vscode-demo, and consolidation work.

  5. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Resource child #364 is complete through merged #368 (83b2c4e8). WebScene now preserves unchanged Code's host-owned local-resource admission results through streamed Service Worker response tees, cache validation, ranges, fail-closed denials, late-message retirement, and 100-cycle teardown without adding filesystem authority.

    #266 now advances to the remaining localhost port-mapping semantic, then final product/offline acceptance.

  6. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Resource child #371 is attached under #266 from exact WebScene 83b2c4e8. It qualifies only the generic Fetch redirect step after unchanged Code's host-authorized localhost mapping reply. Code/AppScene retain mapping, tunnel, network-permission, and socket authority; the slice is disjoint from File System Access lifetime #370, AppScene#156, CSS #366/PR #369, AppScene source, WebSocket transport, #76, and vscode-demo.

  7. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Resource-plane update: #371 / #374 merged as c9079ba7dd9488f1ed59520444703c370c9afd20. The unchanged Code OSS v6 load-localhost / did-load-localhost exchange now reaches the host-authorized target through WebScene's existing loader with browser-compatible redirect modes and fail-closed invalid/loop handling. This adds no mapping, tunnel, WebSocket, filesystem, origin, or CSP authority. Direct Linux/macOS/portable-V8/native-document gates and the 100-cycle Chrome oracle passed.

  8. 10 remaining items

  9. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Exact audited base: 51f71381bda9015b64cf0566534e209f8bfa9986.

    The unchanged Markdown prelude now advances through iframe navigation, document replacement, fallback activation, and ResizeObserver setup after #399. The first remaining product call that fails is the enabled find bridge: contentWindow.find is absent and getSelection() has no persistent range state.

    This child owns only realm-local Selection state, the Code OSS Window.find argument subset, reset on replacement/detach, and focused Chrome/native/performance/lifecycle evidence. It will touch V8 DOM/window bindings, realm lifecycle state, focused browser-DOM tests, and a dedicated contract/profile. It excludes #400 File System paths, #401 CSS paths, AppScene packaging, cross-origin capability expansion, cross-frame/Shadow DOM search, input routing, and accessibility publication.

  10. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Completed by #411, merged as d355d3fd021d792f97f5010aad5951ff7776b772.

    Final evidence: unchanged Code OSS Markdown reaches the nested frame find/find-stop bridge; Chrome 153 and native pass the focused contract 10/10; the exact Code-shaped nested-frame sequence passes; opaque/cross-origin access remains fail-closed; 100 create/navigate/find/remove cycles retain no listeners or native DOM nodes. The 100,000-text-node gate measured p95 17.67 ms (50 ms limit), flat V8 heap (1,390,808 bytes before/after), native nodes 7 -> 7, and bounded high-water RSS. Direct exact-head Linux, native-document, portable V8, and both NativeAOT checks passed; focused macOS product gates passed locally.

  11. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Exact implementation base: d355d3fd021d792f97f5010aad5951ff7776b772.

    The Chrome 153 oracle establishes the next product-visible invariant: frame.contentWindow.focus() sets the outer activeElement to the iframe, the child document becomes focused with BODY active, inner focus keeps iframe ownership, and outer focus exits the child and resets its active element. The unchanged Code OSS prelude uses exactly this call for host focus and visible-frame replacement.

    Owned paths will be the generic V8 focus/window bindings and state, focused native browser-DOM/input tests, and one dedicated browser/native contract/profile. The implementation will not touch CSS, File APIs, packaging, AppScene, keyboard routing, accessibility publication, or #267 navigation/origin/CSP behavior. Opaque/cross-origin access remains fail-closed, and top-level Window.focus() keeps its typed host request.

  12. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Completed by #416, merged as dd39f118b8eba301f1884740e8b25573f49d687e.

    Evidence:

    • Chrome 153 oracle: 6/6 focus ownership assertions passed.
    • Native WebPlatformSubset: 1/1 document, 6/6 subtests passed.
    • Exact navigated Code-shaped Markdown fake.html plus document.open/write/close focus handoff passed.
    • Same-origin child focus emits no host activation request; top-level focus emits exactly one typed request; opaque/cross-origin access remains fail-closed.
    • Post-rebase native lifecycle gate: 100 create/focus/inner-focus/remove cycles, p95 0.476 ms (10 ms limit), V8 heap 1,417,252 -> 1,417,252 bytes, native nodes 7 -> 7, RSS 44.9 -> 46.2 MiB (64 MiB limit).
    • Hosted macOS ARM64 and portable V8 passed at exact PR head 8f2732033761d86a936ab3ae7f308a160f8f1529; remaining broad tails were canceled under the fast-merge policy.
  13. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Resource-plane progress: #419 completed through #422 and merged as 2f0ae98816a3450b048efb994e283ef35a55ed17.

    The generic Chrome/native contract now proves that a navigated nested webview resource keeps its own FetchEvent.clientId, derives the webview id from that child URL, discovers the outer admission owner through clients.matchAll(), consumes a two-chunk streamed response without host fallback, and retires every nested client across 100 cycles. Chrome 153 and native both passed 4/4 assertions; native measured 2.03 ms p95 with byte-exact stable V8 heap and about 0.91 MiB post-teardown RSS growth. Linux, macOS, and portable V8 passed at the exact PR head.

    This slice is test/profile only because current main already implements the reduced semantics. It did not touch #81/#421, #246, AppScene, consolidation, or vscode-demo. The separate #81/#421 iframe Worker/MessagePort bootstrap remains the current packaged-product blocker; after it lands, #264 still needs the representative unchanged webview consumer matrix and cumulative product acceptance.

  14. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Resource-plane milestone: #428/#431 merged as 99e852a3de72e4ceb4b47745b3cbf2f957495b9d, completing #266.

    The exact unchanged Code OSS 645f29c version-6 worker now passes one Chrome/native matrix for Markdown plus notebook, custom editor, extension detail, Chat/MCP, Mermaid/Codicon, Simple Browser, and release-notes assets. It also proves fail-closed admission, 32 concurrent 1 MiB responses, one validator-backed 64 KiB body reused over 100 requests, bounded engine-owned memory/RSS high-water, and 100-cycle latency/lifecycle behavior. Chrome passed 11/11; packaged native measured 0.15 ms p95 with 1.49 MiB heap and 86 KiB external memory after collection; hosted portable V8 passed at the exact PR head.

    No runtime or authority change was needed. Durable cross-engine CacheStorage is not used by this unchanged worker's resource protocol. #264 remains open for the current MessagePort/package bootstrap work and cumulative unchanged-product UI acceptance; those paths were not changed by #431.

  15. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Current-main implementation update: #440/#442 and #443/#445 are merged, with cumulative main now 4ea2feebd0dd7f2f08dfa1a8bfbbe1ca5f3d6c3b.

    The #268 lane now implements the exact Code OSS Select All forwarding path across nested documents and exposes Document.queryCommandSupported for the already-implemented copy/cut/paste/selectAll command set. The Selection change reuses the existing Window.find text index and supports multi-node selected text. Neither slice adds authority or touches AppScene, vscode-demo, or consolidation #76.

    Per the implementation-only directive, all new WPT/Chromium/native/performance/lifecycle/CI and installed-package evidence is deferred and recorded on #440 and #443. #264 remains open. #267 still lacks CSP/Permissions Policy, broader origin/navigation/replacement teardown, and cumulative Markdown security evidence; #268 still lacks the event/input/link/download/accessibility and cumulative unchanged-consumer matrix.

  16. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Implementation-wave update: WebScene #448 / PR #450 merged as aa276b17c42eee22dd067f6872afc4b2d02f4034 from baseline a263f4e, adding HTMLIFrameElement.allow reflection and inherited iframe Permissions Policy admission for VS Code OSS clipboard-read / clipboard-write before native host handoff.

    The focused implementation covers the exact allow declarations authored by unchanged webviewElement.ts and browser/pre/index.html; CSP, other policy-controlled features, response headers, and the remaining #267 lifecycle/security matrix are still outstanding. Per the implementation-only priority, focused tests, benchmarks, broad native builds, package qualification, and CI waits are recorded as cumulative validation debt. WebScene #76, AppScene #65, and vscode-demo #1 remain unmerged.

  17. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Implementation-wave update: WebScene #454 / PR #455 merged as a2f873e822fd83af9a41013989aabbf94b520bf3, adding parser-order meta CSP script admission for nested iframe documents. Disallowed external scripts are stopped before prefetch/evaluation; VS Code's pre-meta API bootstrap and nonce-authorized Markdown scripts remain admitted.

    The remaining #267 CSP surface includes response headers, non-script directives, violation reporting, hashes, dynamic insertion, and multiple-policy intersection alongside the broader lifecycle/security matrix. Per the implementation-only priority, focused tests, benchmarks, broad native builds, package qualification, and CI waits remain cumulative validation debt. WebScene #76, AppScene #65, and vscode-demo #1 remain unmerged.

  18. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Implementation-wave update: WebScene #460 / PR #461 merged as c19fbc36ddd36d23eb9116b354295acf05ee9e58, adding per-frame navigation generations so stale same-URL/source fetch, yielded script hydration, and DOMContentLoaded/load continuation cannot complete after a newer iframe.src assignment or document.open() replacement.

    The remaining #267 lifecycle surface includes explicit reload/history, beforeunload/pagehide and error ordering, cross-origin WindowProxy behavior, and cumulative teardown/performance evidence. Per the implementation-only priority, focused tests, benchmarks, broad native builds, package qualification, and CI waits remain cumulative validation debt. WebScene #76, AppScene #65, and vscode-demo #1 remain unmerged.

  19. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Final implementation-wave update for this lane: WebScene #466 / PR #467 merged as 6363114a6b75c6d5905adabd491820194ed4e174, dispatching one pagehide to outgoing nested Windows before iframe navigation or detach teardown. This closes the event used by unchanged VS Code active-frame replacement and Markdown Editor scroll persistence.

    Remaining #267 work is broader lifecycle/security and validation: beforeunload/visibility/unload, explicit reload/history, cross-origin proxies, remaining CSP/policy directives, deterministic error ordering, and cumulative teardown/performance/product evidence. Focused tests, benchmarks, broad native builds, package qualification, and CI waits remain recorded validation debt. WebScene #76, AppScene #65, and vscode-demo #1 remain unmerged.

  20. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Nested-webview interaction progress: #470 / PR #472 merged as ff94bad2d8d7148948bc44644e4da1b6d5280fa9.

    WebScene now distinguishes real host-ABI pointer/keyboard events from script-created Events and HTMLElement.click(). This clears unchanged Code OSS's isTrusted guards for nested link and keyboard forwarding without adding navigation, download, context-menu, clipboard, or command authority.

    Validation is intentionally deferred under the implementation-only directive: no tests, benchmarks, builds, package checks, CI waits, or installed-product runs were performed. #268 still owns nested coordinate/context-menu routing, keyboard traversal and full keybinding acceptance, anchor/default-action and download handoff, drag/drop, accessibility publication, and cumulative unchanged-consumer evidence. #267 still owns the remaining lifecycle/security and reload/history work. WebScene #76, AppScene #65, and vscode-demo #1 remain unmerged.

  21. wieslawsoltes commented on Sep 21, 2026

    @wieslawsoltes
    CollaboratorAuthor

    21 September 2026 exact-head native checkpoint: unchanged Code OSS 645f29cc, merged WebScene 5b4739c8, merged AppScene 36d7a82e, signed installed-SDK/CLI diagnostic Release. The opt-in acceptance overlay invoked the unchanged markdown.showPreviewToSide command after a byte-exact remote README lifecycle; the command resolved and [Preview] README.md appeared, but the pane remained white. Native frame snapshots measured a 1440×940 workbench and a 0×0 outer webview iframe, 0×0 fixed .webview-overlay-content, and 0×0 absolute overlay root. The nested fake.html frame was created inside the virtual-HTTPS prelude and was also 0×0. The prior fake.html manifest fix is present; it did not complete visual acceptance.

    Unchanged Code OSS overlayLayoutElement.ts uses CSS Anchor Positioning (anchor-name, position-anchor, anchor(), anchor-size()) for this overlay; no matching implementation was found in the checked WebScene native sources. WebScene #903 (child of CSS epic #235) now owns a product-neutral Chrome/native geometry contract, absolute-inset isolation, implementation, and panel/resize performance gates. WebScene #904 (child of #267) separately owns a nested reflected-URL defect. Focused PR #905 implements a tested connected-owner getter slice; actual nested requests must still be verified separately. See local demo commit 69f4b43b and docs/validation/markdown-preview-layout-20260921.md for exact logs, screenshot and limits. Keep this issue open until actual Markdown paints and Chromium geometry, security, lifecycle, memory/CPU and release acceptance pass. Two earlier cold-start attempts also missed the 2-second Explorer paint gate (2198.78 and 2318.83 ms); track under WebScene #252/#243.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicTracks a coordinated set of focused issuesvscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions