Parents: #267, #81
Release owner: SceneTech/AppScene#130
Reproduction
The exact Code OSS package at WebScene 5b97aac fetches webWorkerExtensionHostIframe.html successfully, but its inline bootstrap never posts vscode.bootstrap.nls. The file declares:
script-src ... 'sha256-daEgfo2VIXpx2Np71KqCCbkeQwv+68vPrx54XRcbdcs=' ...
The declared digest exactly matches the 5,588-byte inline script. WebScene's nested-document CSP parser recognizes that a hash source exists and consequently disables unsafe-inline, but frame_script_policy_allows never calculates or compares the script hash. It therefore rejects every hash-authorized inline script. The frame is fetched again after VS Code retries, with the same result, and #81 fails before MessagePort transfer.
Fix
- Compute SHA-256 over the exact inline script bytes parsed from the document.
- Encode the digest as standard padded Base64 and compare the source expression case-sensitively.
- Preserve nonce and external-source behavior; keep
unsafe-inline suppressed when any nonce/hash expression is present.
- Reject malformed and nonmatching hashes without executing script.
SHA-384/SHA-512 expressions remain fail-closed until matching digest providers are implemented; they must not accidentally enable inline execution.
Gates
- Browser/WPT-derived positive SHA-256, wrong digest, whitespace-sensitive source, mixed nonce/hash,
unsafe-inline suppression, malformed value, and meta-policy-order contracts.
- Native Code OSS-shaped iframe fixture using the exact published digest and the real bootstrap message structure.
- Repeat bootstrap/teardown with bounded nodes, wrappers, heap/RSS, task queues, and zero extra idle frames.
- Exact packaged Code OSS evidence: one iframe bootstrap, transferred MessagePort, Ready/Initialized handshake, and no application source change.
Performance
Hash each parser-discovered inline script at most once during policy admission. Do not add DOM scans, retained visual nodes, timers, or frame publications.
Parents: #267, #81
Release owner: SceneTech/AppScene#130
Reproduction
The exact Code OSS package at WebScene
5b97aacfetcheswebWorkerExtensionHostIframe.htmlsuccessfully, but its inline bootstrap never postsvscode.bootstrap.nls. The file declares:The declared digest exactly matches the 5,588-byte inline script. WebScene's nested-document CSP parser recognizes that a hash source exists and consequently disables
unsafe-inline, butframe_script_policy_allowsnever calculates or compares the script hash. It therefore rejects every hash-authorized inline script. The frame is fetched again after VS Code retries, with the same result, and #81 fails before MessagePort transfer.Fix
unsafe-inlinesuppressed when any nonce/hash expression is present.SHA-384/SHA-512 expressions remain fail-closed until matching digest providers are implemented; they must not accidentally enable inline execution.
Gates
unsafe-inlinesuppression, malformed value, and meta-policy-order contracts.Performance
Hash each parser-discovered inline script at most once during policy admission. Do not add DOM scans, retained visual nodes, timers, or frame publications.