Skip to content

Preserve authored iframe src during remote document resolution #896

Description

@wieslawsoltes

Parent: #267 (nested-document lifecycle); related webview epic #264 and unchanged Code OSS installed acceptance #227.

Proven merged-main bug (21 September 2026)

WEBSCENE_NATIVE_ENGINE_TEST_FILTER=iframe-navigation-lifecycle fails on clean merged WebScene 06d6a4f5, reproduced again on merged 99cf2f86 without any local runtime changes. The existing gate reports 101 beforeunload calls, exactly one ordered pagehide/visibilitychange/unload, the correct allowed document and a stable WindowProxy. Only reentrantUnloadBlocked fails. A temporary read-only observation added to the test shows its requested authored ./fake.html?id=allowed became https://iframe-navigation.test/fake.html?id=allowed when read through frame.getAttribute('src'). This is source representation drift, not evidence of a competing reentrant unload navigation.

WebScene currently writes the resolved absolute URL back into node.attributes["src"] in webscene_v8_runtime_dom_core.inc::enqueue_iframe_hydration_if_needed and again in webscene_v8_runtime_cache_and_frames.inc after loading the remote document. The iframe's reflected src must retain the authored attribute; the absolute request/document URL belongs in a separate internal resolution/committed-origin field. Replacing the authored attribute also risks Code OSS comparing an iframe's markup/attributes across updates.

Proposed focused fix / gates

Keep the authored relative, Unicode, query-bearing or absolute src unchanged through prefetch, final document load, same/cross-origin navigation, cancel/reentrant beforeunload, remote-load failure, and detach. Continue to use a separately pinned resolved URL for network and committed browsing-context origins, including redirects, without widening same-origin DOM access. Repair the existing iframe-navigation-lifecycle native gate, add a focused positive authored-getAttribute vs absolute contentWindow.location.href regression and wrong-origin/redirect negatives; keep WPT iframe attribute reflection/parsing and 100-cycle heap/queue bounds. Preserve exact event order and no extra requests. Run related native and CI runners before a focused PR merge; rebuild installed unchanged Code OSS afterward. No VS Code source edits or browser shell dependency.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingvscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions