Active implementation checkpoint — 19 September 2026
Exact upstream heads are WebScene 91fa294f5616f94ba5a24b3b08cdf7307166fc6e and AppScene fe14e7b775d347693d6526b7c4d49c0dca082e52; unchanged Code OSS is 645f29cc3176500b4b5762ba887cf2a7f0ffdf2c. Local vscode-demo is c543d2ca9ff97f3c9e256c5eda4193fad5b53c13 and remains intentionally unpushed with Actions disabled.
Merged Linux exact-device work remains complete through WebScene #654 and AppScene #270. Linux CLIPBOARD/PRIMARY and inbound/outbound Xdnd are merged through WebScene #658 and AppScene #280. CSS animation direction #659/#660 and fill modes #661/#662 are merged. The current-main native compiler failure exposed by #662 is tracked and fixed by #663/#664; generated selectors now preserve compiled namespace-aware compound and attribute data. #666/#667 binds the remaining native test consumer to the namespace-aware compiler API, and #668/#669 restores complete structured selector parity comparisons. #665/#670 implements demand-free animation pause/resume, and #671/#673 enforces parser package size with both ratio and absolute byte budgets, and #672/#678 implements bounded eight-track animation-list coordination; #674/#681 implements zero-time/count semantics, #679/#680/#682 updates the native stale-track contract for inactive authored list slots, and #675/#683 adds bounded translate/scale keyframe sampling and retained paint composition. #684/#685 refreshes the generated Code OSS ledger and exact property identity count exposed by the post-merge main jobs. #676/#686 adds bounded retained ::before/::after animation lifecycle, scoped paint, owner events, cleanup, and demand-free settled state. Full-V8 package portability epic #687 is implemented by #688/#691 for GCC, #689/#692 for MSVC enum/ABI boundaries, #690/#693 for bounded embedded source literals, #694/#695 for const cascade roots, and #696/#697 for native test syntax. #677/#698 adds bounded retained WAAPI with document/element caps, lifecycle settlement, and demand-free inactive states. #699/#700 restores the 384-byte native document footprint by moving WAAPI-only maps and event state behind one lazy auxiliary allocation. #476/#702 adds bounded asynchronous document fetch and stale-generation suppression for dynamically inserted CSS imports, complementing #480/#484 authored-import reflection. #701/#703 adds browser-shaped Worker options, inherited credential policy, final response/CORS enforcement, generation-safe failure, and bounded slot retirement. #704/#705 adds an optional bounded redirect ledger and per-hop Worker status/scheme/loop/downgrade/origin/CORS/credential checks. #706/#707 extracts bounded request-header ABI v5 onto current main; AppScene #281/#282 and vscode-demo #10 populate the ledger in their host providers.
One-agent mode is enforced. The sole implementation agent is implementing bounded interactive reportValidity feedback under #708; no other implementation agent is active. Static fill does not sustain frame demand, and new animation work must preserve that bound without per-frame cascade, selector, or visual-tree churn.
Consolidations remain open and unmerged: WebScene #76 at b1f4977691938e636c1e16ac1c2f37c4d2128f4c, AppScene #65 at 0c018306458050a66a19d2c84abd3cf65a20832c, and vscode-demo #1. WebScene #662 and #681 portable V8 contracts passed. Focused #682 native document and Linux SDK runs 35448768204 and 35448768281 passed; #683 portable V8 contracts passed. The failed #683 current-main generated-ledger/property-count gates are repaired by #684/#685, and Linux CI job 105914816775 passed. Full-V8 Linux/Windows RID portability repairs are merged through #691-#697; current-main CI/NuGet runs 35454910272 and 35454910266 are retained; superseded PR, previous-main, and consolidation runs were cancellation-requested. AppScene #282 current-main companion run 35454940645 passed.
Ordered next work: #708 interactive validity feedback, then current-main CI/package triage and the remaining focused CSS and acceptance backlog, then physical Linux pixels, synchronization/device-loss/resize/soak/performance, VM/computer-use, and unchanged Code OSS Release qualification. Rich clipboard MIME, MULTIPLE/SAVE_TARGETS, and the recorded desktop-service/cross-platform backlog remain open.
Parent: #81
Release epic: #227
Related lifecycle owner: #288
Nested-document security owner: #267
Proven remaining implementation gap
Dedicated Worker execution, bounded slot recycling, structured clone, transferred MessagePort operation, and Code OSS worker bootstrap are already on main. The remaining implementation-specific gap recorded by #81 is browser-compatible WorkerOptions.credentials, module/classic worker fetch policy, and deterministic load-failure settlement.
Scope
- Parse and validate
WorkerOptions, including type, credentials, and name, with browser-shaped defaults and exceptions.
- Apply
omit, same-origin, and include credential policy to classic and module worker script/dependency fetches without bypassing the admitted resource/origin contract.
- Enforce same-origin/CORS behavior for worker entry scripts and module dependency graphs; preserve redirect/final-URL policy and imported relative URL bases.
- Deliver constructor/startup, network, syntax, module-resolution, and policy failures once through the owning realm's error path; never leave a live execution slot or unresolved queued work.
- Keep worker startup asynchronous and bounded. Navigation, termination, and engine teardown must invalidate late fetch/compile completion by generation.
Constraints
No Code OSS source changes, browser process, Electron, CEF, or WebView. Do not alter the independent MessagePort reachability work in #288 or general iframe navigation/security ownership in #267. Preserve the current 64-live-worker capacity and stopped-wrapper bound.
Deferred acceptance debt
Under the current implementation-first directive, this issue may merge after diff checks. Browser/WPT comparison, native execution, throughput, heap/RSS, lifecycle, package, and cross-platform CI remain release-acceptance debt under #81/#227.
Active implementation checkpoint — 19 September 2026
Exact upstream heads are WebScene
91fa294f5616f94ba5a24b3b08cdf7307166fc6eand AppScenefe14e7b775d347693d6526b7c4d49c0dca082e52; unchanged Code OSS is645f29cc3176500b4b5762ba887cf2a7f0ffdf2c. Local vscode-demo isc543d2ca9ff97f3c9e256c5eda4193fad5b53c13and remains intentionally unpushed with Actions disabled.Merged Linux exact-device work remains complete through WebScene #654 and AppScene #270. Linux CLIPBOARD/PRIMARY and inbound/outbound Xdnd are merged through WebScene #658 and AppScene #280. CSS animation direction #659/#660 and fill modes #661/#662 are merged. The current-main native compiler failure exposed by #662 is tracked and fixed by #663/#664; generated selectors now preserve compiled namespace-aware compound and attribute data. #666/#667 binds the remaining native test consumer to the namespace-aware compiler API, and #668/#669 restores complete structured selector parity comparisons. #665/#670 implements demand-free animation pause/resume, and #671/#673 enforces parser package size with both ratio and absolute byte budgets, and #672/#678 implements bounded eight-track animation-list coordination; #674/#681 implements zero-time/count semantics, #679/#680/#682 updates the native stale-track contract for inactive authored list slots, and #675/#683 adds bounded translate/scale keyframe sampling and retained paint composition. #684/#685 refreshes the generated Code OSS ledger and exact property identity count exposed by the post-merge main jobs. #676/#686 adds bounded retained
::before/::afteranimation lifecycle, scoped paint, owner events, cleanup, and demand-free settled state. Full-V8 package portability epic #687 is implemented by #688/#691 for GCC, #689/#692 for MSVC enum/ABI boundaries, #690/#693 for bounded embedded source literals, #694/#695 for const cascade roots, and #696/#697 for native test syntax. #677/#698 adds bounded retained WAAPI with document/element caps, lifecycle settlement, and demand-free inactive states. #699/#700 restores the 384-byte native document footprint by moving WAAPI-only maps and event state behind one lazy auxiliary allocation. #476/#702 adds bounded asynchronous document fetch and stale-generation suppression for dynamically inserted CSS imports, complementing #480/#484 authored-import reflection. #701/#703 adds browser-shaped Worker options, inherited credential policy, final response/CORS enforcement, generation-safe failure, and bounded slot retirement. #704/#705 adds an optional bounded redirect ledger and per-hop Worker status/scheme/loop/downgrade/origin/CORS/credential checks. #706/#707 extracts bounded request-header ABI v5 onto current main; AppScene #281/#282 and vscode-demo #10 populate the ledger in their host providers.One-agent mode is enforced. The sole implementation agent is implementing bounded interactive reportValidity feedback under #708; no other implementation agent is active. Static fill does not sustain frame demand, and new animation work must preserve that bound without per-frame cascade, selector, or visual-tree churn.
Consolidations remain open and unmerged: WebScene #76 at
b1f4977691938e636c1e16ac1c2f37c4d2128f4c, AppScene #65 at0c018306458050a66a19d2c84abd3cf65a20832c, and vscode-demo #1. WebScene #662 and #681 portable V8 contracts passed. Focused #682 native document and Linux SDK runs35448768204and35448768281passed; #683 portable V8 contracts passed. The failed #683 current-main generated-ledger/property-count gates are repaired by #684/#685, and Linux CI job105914816775passed. Full-V8 Linux/Windows RID portability repairs are merged through #691-#697; current-main CI/NuGet runs35454910272and35454910266are retained; superseded PR, previous-main, and consolidation runs were cancellation-requested. AppScene #282 current-main companion run35454940645passed.Ordered next work: #708 interactive validity feedback, then current-main CI/package triage and the remaining focused CSS and acceptance backlog, then physical Linux pixels, synchronization/device-loss/resize/soak/performance, VM/computer-use, and unchanged Code OSS Release qualification. Rich clipboard MIME, MULTIPLE/SAVE_TARGETS, and the recorded desktop-service/cross-platform backlog remain open.
Parent: #81
Release epic: #227
Related lifecycle owner: #288
Nested-document security owner: #267
Proven remaining implementation gap
Dedicated Worker execution, bounded slot recycling, structured clone, transferred MessagePort operation, and Code OSS worker bootstrap are already on main. The remaining implementation-specific gap recorded by #81 is browser-compatible
WorkerOptions.credentials, module/classic worker fetch policy, and deterministic load-failure settlement.Scope
WorkerOptions, includingtype,credentials, andname, with browser-shaped defaults and exceptions.omit,same-origin, andincludecredential policy to classic and module worker script/dependency fetches without bypassing the admitted resource/origin contract.Constraints
No Code OSS source changes, browser process, Electron, CEF, or WebView. Do not alter the independent MessagePort reachability work in #288 or general iframe navigation/security ownership in #267. Preserve the current 64-live-worker capacity and stopped-wrapper bound.
Deferred acceptance debt
Under the current implementation-first directive, this issue may merge after diff checks. Browser/WPT comparison, native execution, throughput, heap/RSS, lifecycle, package, and cross-platform CI remain release-acceptance debt under #81/#227.