Parent epic: #264; nested security/lifecycle owner: #267; follows merged WebScene #893 and AppScene #401. Installed Release owner: SceneTech/AppScene#398.
Exact native reproduction (21 September 2026)
Unchanged Code OSS 645f29cc with exact merged WebScene 06d6a4f5 and AppScene 1142abe was built as a full, signed installed-CLI Release at vscode-demo/dist/appscene-release-1142abe-06d6a4f5-markdown/Code OSS AppScene.app (709 MiB). codesign --verify --deep --strict passes. Native System Events keyboard input opens real remote seven-byte beta/README.md, then Markdown: Open Preview to the Side. The tab stays blank. The formerly missing navigator.serviceWorker and worker-script-fetch exceptions have disappeared after focused #893/#401.
The first isolated HTTPS prelude exception is now Uncaught TypeError: Cannot read properties of null (reading 'postMessage'), inline module line 313 (physical pre/index.html line 328), frame ~8996, when unchanged HostMessaging.signalReady() executes window.parent.postMessage({target:ID,channel:'webview-ready',data:{}},parentOrigin,[this.channel.port2]). The prelude validates the generated hostname against its parent-origin hash first. WebScene webscene_v8_runtime_cache_and_frames.inc::install_frame_globals explicitly assigns window.parent and window.top null whenever the parent cannot read the cross-origin child DOM. Browser cross-origin WindowProxy still permits parent messaging and MessagePort transfer without granting DOM access. The missing restricted parent channel prevents webview handshake/content, even with the worker script loaded.
Evidence: vscode-demo/build/appscene-webview-398/merged-1142abe-06d6a4f5/native-preview.log and preview-parent-window-null.png; prior merged-head run in merged-06d6a4f5 proves the worker URL issue was separate.
Proposed product-neutral fix and focused gates
Expose a stable, restricted cross-origin window.parent reference in child realms, with postMessage routing through the existing bounded structured-clone/targetOrigin/transfer queue to the immediate owning browsing context. Preserve a restricted window.top reference when applicable. Never expose the real parent global/document/storage or allow arbitrary property access; parent contentDocument stays denied. Establish sender origin from the child realm, stable MessageEvent.source proxy across navigation, exact targetOrigin delivery/denial, once-only MessagePort ownership, iframe removal/lifecycle release, inherited opaque sandbox, frame nesting, and bounded queue/heap tests. Add a focused native iframe fixture for isolated HTTPS allow-scripts allow-same-origin, positive child-to-parent ready/transfer, negative parent DOM leak and wrong targetOrigin. Confirm the old same-origin iframe and ServiceWorker tests still pass; run related CI and full installed Markdown/visual test before closing #264/SceneTech/AppScene#398. Keep unchanged Code OSS and no Electron/CEF/WebView.
Parent epic: #264; nested security/lifecycle owner: #267; follows merged WebScene #893 and AppScene #401. Installed Release owner: SceneTech/AppScene#398.
Exact native reproduction (21 September 2026)
Unchanged Code OSS
645f29ccwith exact merged WebScene06d6a4f5and AppScene1142abewas built as a full, signed installed-CLI Release atvscode-demo/dist/appscene-release-1142abe-06d6a4f5-markdown/Code OSS AppScene.app(709 MiB).codesign --verify --deep --strictpasses. Native System Events keyboard input opens real remote seven-bytebeta/README.md, then Markdown: Open Preview to the Side. The tab stays blank. The formerly missingnavigator.serviceWorkerand worker-script-fetch exceptions have disappeared after focused #893/#401.The first isolated HTTPS prelude exception is now
Uncaught TypeError: Cannot read properties of null (reading 'postMessage'), inline module line 313 (physicalpre/index.htmlline 328), frame ~8996, when unchangedHostMessaging.signalReady()executeswindow.parent.postMessage({target:ID,channel:'webview-ready',data:{}},parentOrigin,[this.channel.port2]). The prelude validates the generated hostname against its parent-origin hash first. WebScenewebscene_v8_runtime_cache_and_frames.inc::install_frame_globalsexplicitly assignswindow.parentandwindow.topnull whenever the parent cannot read the cross-origin child DOM. Browser cross-origin WindowProxy still permits parent messaging andMessagePorttransfer without granting DOM access. The missing restricted parent channel prevents webview handshake/content, even with the worker script loaded.Evidence:
vscode-demo/build/appscene-webview-398/merged-1142abe-06d6a4f5/native-preview.logandpreview-parent-window-null.png; prior merged-head run inmerged-06d6a4f5proves the worker URL issue was separate.Proposed product-neutral fix and focused gates
Expose a stable, restricted cross-origin
window.parentreference in child realms, withpostMessagerouting through the existing bounded structured-clone/targetOrigin/transfer queue to the immediate owning browsing context. Preserve a restrictedwindow.topreference when applicable. Never expose the real parent global/document/storage or allow arbitrary property access; parentcontentDocumentstays denied. Establish sender origin from the child realm, stableMessageEvent.sourceproxy across navigation, exact targetOrigin delivery/denial, once-onlyMessagePortownership, iframe removal/lifecycle release, inherited opaque sandbox, frame nesting, and bounded queue/heap tests. Add a focused native iframe fixture for isolated HTTPSallow-scripts allow-same-origin, positive child-to-parent ready/transfer, negative parent DOM leak and wrong targetOrigin. Confirm the old same-origin iframe and ServiceWorker tests still pass; run related CI and full installed Markdown/visual test before closing #264/SceneTech/AppScene#398. Keep unchanged Code OSS and no Electron/CEF/WebView.