Parent: #267, following #896 and #897; related webview epic #264.
Proven next nested-document failure
The existing WEBSCENE_NATIVE_ENGINE_TEST_FILTER=iframe-navigation-lifecycle gate now reaches nested same-document history after the authored src and shared fragment URL corrections. history.replaceState(..., "#one"), pushState(..., "#two"), and history.back() update the child to the correct fake.html?id=history-reload#one URL, history.length=2 and history.state.step=1; a nested timer also runs. However the parent-owned stable frame.contentWindow proxy's registered popstate and hashchange callbacks are never invoked, so it cannot schedule its reload and the test times out. frame_window_add_event_listener in webscene_v8_runtime_html.inc only registers DOMContentLoaded and innerWindowLoad, while dispatch_same_document_history_event in webscene_v8_runtime_dom_core.inc dispatches only on the current inner global. This is a distinct event-forwarding/lifecycle gap after URL correction.
Proposed focused gate
Keep popstate and hashchange handlers attached to a same-origin WindowProxy through same-document traversal and replacement, dispatch them once with the correct event target, state, oldURL/newURL and order, remove them correctly, and never expose these events or child DOM to a cross-origin owner. Preserve bounded listeners across reload/detach and no stale tasks. Run the full iframe navigation/history native test, wrong-origin negatives, 100-cycle listener/resource/perf gates and related CI before merging the focused PR stack. No Code OSS changes.
Parent: #267, following #896 and #897; related webview epic #264.
Proven next nested-document failure
The existing
WEBSCENE_NATIVE_ENGINE_TEST_FILTER=iframe-navigation-lifecyclegate now reaches nested same-document history after the authoredsrcand shared fragment URL corrections.history.replaceState(..., "#one"),pushState(..., "#two"), andhistory.back()update the child to the correctfake.html?id=history-reload#oneURL,history.length=2andhistory.state.step=1; a nested timer also runs. However the parent-owned stableframe.contentWindowproxy's registeredpopstateandhashchangecallbacks are never invoked, so it cannot schedule its reload and the test times out.frame_window_add_event_listenerinwebscene_v8_runtime_html.inconly registersDOMContentLoadedandinnerWindowLoad, whiledispatch_same_document_history_eventinwebscene_v8_runtime_dom_core.incdispatches only on the current inner global. This is a distinct event-forwarding/lifecycle gap after URL correction.Proposed focused gate
Keep
popstateandhashchangehandlers attached to a same-origin WindowProxy through same-document traversal and replacement, dispatch them once with the correct event target, state, oldURL/newURL and order, remove them correctly, and never expose these events or child DOM to a cross-origin owner. Preserve bounded listeners across reload/detach and no stale tasks. Run the full iframe navigation/history native test, wrong-origin negatives, 100-cycle listener/resource/perf gates and related CI before merging the focused PR stack. No Code OSS changes.