Repository navigation
Stream and cache admitted Code OSS webview resources #266
Description
Activity
- addedvscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integrationPlanned for the AppScene/WebScene VS Code OSS integration
on Sep 17, 2026 First unchanged-product resource-plane failure
The stamped exact-head run now clears #265's Service Worker control boundary and reaches
webview ready, but the right Markdown pane stays blank. This is the first deterministic #266 product boundary.Evidence from
/private/tmp/webscene-265-stamped-run.A3t8FO:- current copied
vscode-demo/README.mdSHA-256:db3dd0a4483949b325f267734c2c58ab3101e04853f2d202e182ecbf51471cb8; will update contentat1789653762786;webview readyat1789653764798(2,012 ms later);- first loader failure at
1789653765919(1,121 ms after ready):http://127.0.0.1:58410/http\\:\\/\\/127\\.0\\.0\\.1\\:58410\\/oss-dev\\/vscode-remote-resource\\; - screenshot
preview-stamped.png: unchanged source is visible on the left; the right preview is blank after 15 seconds; - no old-worker version mismatch remains.
The owning resource path is standards-shaped and already matches this issue: Markdown's generated HTML initially has an empty body and loads extension
pre.js/styles throughwebview.asWebviewUri(...). Code's v6 Service Worker handles those withFetchEvent.respondWith, Clients messaging, Request/Response/Headers, Streams, and CacheStorage. The cumulative #265 branch has no FetchEvent/Streams/CacheStorage implementation by design.A second proven defect affects the first logged URL: WebScene preserves CSS string escapes into resource resolution, so escaped
http\\:\\/\\/...fails scheme detection and gets origin-prefixed. A temporary source-level probe against the unchanged helpers reproducesfirst_css_url()returning the escaped text. That general CSS Syntax defect will be tracked under #235 and linked here. It is adjacent to this product gate, but it should not be implemented inside #266 unless a reduced broker fixture proves it blocks the broker after FetchEvent/Streams exist.Initial #266 stack should therefore start with product-neutral Streams/Body ownership and FetchEvent/
respondWithdispatch contracts, then CacheStorage and the Code client broker, retaining the issue's range/security/performance gates.- current copied
Unchanged-Code API audit and first implementation boundary
The exact
645f29cworker establishes the next runtime boundary more narrowly than the blank pane alone:- the script constructs four static
Responseobjects at evaluation time and registers afetchlistener; - each admitted resource fetch requires
FetchEvent.request,clientId,respondWith(), andwaitUntil()before it can postload-resourceto the controlling window; - the success path then requires a byte
ReadableStream,getReader()/read()/cancel(),tee(), Response body ownership/clone/bodyUsed, and CacheStorage; - when transferable streams are unavailable, unchanged Code deliberately uses the chunk fallback:
TransformStream,writable.getWriter(),write/close/abort/closed, and the readable side; - the worker limits host-response bodies to 32 and the product code already supplies cancellation/teardown hooks.
The cumulative #265 runtime currently has shallow window-oriented
Headers,Request, andResponsewrappers, but no Web Streams globals. Its Service Worker loop dispatches lifecycle and message events only; there is no controlled-resource request queue,FetchEvent,respondWith, or response handoff. Registration/controller readiness therefore does not imply resource interception.The first focused #266 PR will be a product-neutral vertical slice:
- WebIDL-shaped
ReadableStream, default controller, and default reader with byte-chunk ownership, pull/enqueue/close/error, read/cancel, lock release, andtee(); upgrade sharedHeaders/Request/ResponseBody behavior so a Response can own and expose that stream. - WebIDL-shaped
FetchEventwithrequest,clientId,resultingClientId,replacesClientId,preloadResponse,handled,respondWith(), and inheritedwaitUntil()lifetime rules. - Route a same-origin, scope-controlled synthetic subresource through the worker and consume a static streamed Response. Bound pending fetch events and queued body bytes, cancel them on navigation/unregister/shutdown, and reject late/cross-generation results.
This tranche will use selected WPT-derived Streams/FetchEvent assertions plus a Chromium oracle and native top-level/iframe contracts. It will not claim CacheStorage, the Code broker, transferable streams, writable/transform streams, ranges, or full Markdown rendering.
Dependent stack after that slice:
- A — readable body + static FetchEvent vertical: scope above.
- B — writable/transform and structured-clone stream path: writer state/backpressure/abort, chunk fallback, and transferable-stream behavior where supported.
- C — CacheStorage broker: CacheStorage/Cache plus request matching, Response cloning/tee, version replacement, validators, and unchanged Code
load-resourceexchange. - D — resource semantics and cumulative product gate: 200/206/304/401/404, GET/HEAD, range/ETag/Last-Modified, localhost mapping, localResourceRoots/security, 32-body/64-MiB bounds, 100-cycle teardown, and exact Markdown/resources/visual acceptance.
#286 remains the separate general CSS escape-decoding owner. Its escaped-URL fixture will join Stack D after the broker works with an ordinary URL; no CSS-owned files are part of Stack A.
- the script constructs four static
#286 fixture/evidence coordination is ready in local commit
7789039ewithout any Streams or FetchEvent changes. The neutral contract includes the original escaped loopback form alongside ordinary, relative, data, fragment, malformed, decode-once, and blocked escaped-scheme cases. Chromium passes 8/8; native records 0 decoded loopback requests, 4 still-escaped host requests, and 2 forbidden escaped-scheme requests. This fixture can join #266's broker/resource tranche after an ordinary URL works; #286 retains CSS token decoding and integration ownership.Stack A implementation checkpoint
Commit
da18607eonfeature/readable-fetch-event-266implements the first dependency-ordered vertical recorded above:- WebIDL-shaped
ReadableStream, default reader/controller, read/cancel/lock/close/error andtee(); - Response body stream ownership,
bodyUsed, clone/tee, text/arrayBuffer/blob consumption; - service-worker
ExtendableEventandFetchEventwith request/client identifiers,waitUntil(),respondWith(),handled, and active-dispatch/duplicate enforcement; - an internal controlled synthetic dispatch that proves a service worker can return a streamed
206response; - installation in main and nested frame realms, including snapshot builds.
Focused native acceptance passes 100 body/clone/cancel cycles with p95 0.208042 ms and unchanged V8 heap (1,144,292 bytes before/after). Existing 100-cycle service-worker lifecycle and client-message gates remain green; the client queue stays capped at 256 and RSS remains below its 64 MiB growth bound. The Chromium 153 oracle passes 3/3 subtests in 99 ms; evidence is at
/private/tmp/webscene-266-chrome-final/results.jsonin the author environment.This slice deliberately does not claim unchanged Markdown rendering. The exact Code worker's first admitted GET awaits
caches.open().match(), then postsload-resource; its non-transferable chunk path requiresTransformStream. The next native stack entry therefore owns bounded CacheStorage empty-match/request matching plus controlled request routing and TransformStream fallback. Issue #266 remains open for that work and the later range/cache/security/product gates.- WebIDL-shaped
Follow-up profile commit
43d08499promotes the Stack A reduction into the candidate component profile. The exact same contract now passes both runners:- native snapshot build: 1/1 document, 3/3 subtests, 274 ms (
/private/tmp/webscene-266-native-contract/results.json); - Chromium 153: 1/1 document, 3/3 subtests, 110 ms (
/private/tmp/webscene-266-chrome-profile-final/results.json).
The dependent local CacheStorage/request-routing branch has been advanced to exact Stack A head
43d08499; its future GitHub PR will targetfeature/readable-fetch-event-266as a native stack entry.- native snapshot build: 1/1 document, 3/3 subtests, 274 ms (
Stack A is merged through #298 at main
70a2db4c(source head823461b3). Before merge, the exact merge ref against current main116b783dpassed Linux build/tests, native Linux document contracts, portable V8 contracts, macOS ARM64, and NativeAOT Avalonia 12. The MSVC raw-literal regression was removed by preserving the exact 27,687-byte bootstrap as bounded compile-time parts with a fail-closed extractor test.The next GitHub-native child stack is active for CacheStorage empty-match/request routing, WritableStream/TransformStream fallback, and the bounded native worker fetch broker. It will rebase onto merged
70a2db4cbefore publication and carry WPT/Chromium/native correctness plus 100-cycle latency, memory, retirement, and lifecycle gates. This issue remains open because visible unchanged Markdown Preview rendering is still the cumulative product exit condition.Resource-plane Stack B/C publication
The post-#298 resource work is split into a visible native GitHub stack on merged main
70a2db4c:- Add CacheStorage controlled fetch broker #303 — CacheStorage + controlled request broker (
22c095f1, basemain): bounded worker-local Cache/CacheStorage, empty match and cloned response storage, 32-request asynchronous Window.fetch → worker FetchEvent broker, host fallback, rejected response propagation, generation retirement, unregister/shutdown, and MSVC-safe worker bootstrap literals. - Add TransformStream resource fallback #304 — WritableStream/TransformStream fallback (
18a19fa2, basefeature/cache-storage-fetch-broker-266): ordered writerwrite/close/abort/closedsemantics and the readable response side used by unchanged Code's chunk fallback.
The order differs from the earlier provisional B/C list because the TransformStream product path needs a real controlled request and CacheStorage's initial empty match to be meaningful. The ownership remains unchanged and the upper PR is cumulatively validated.
Cumulative top evidence:
- clean snapshot/native compilation;
- portable raw-literal regression 2/2;
- native 100-cycle controlled resource gate p95 0.196 ms, V8 heap 1,161,272 → 1,161,272 bytes, peak RSS 38,191,104 → 49,463,296 bytes;
- native candidate contract 1/1 documents, 3/3 subtests, 139 ms;
- Google Chrome 153 oracle 1/1 documents, 3/3 subtests, 138 ms;
- isolated Chrome process cleanup confirmed.
#266 remains open. These entries intercept Window fetches and prove the Code-shaped cache/chunk pipeline; parser/image/style request interception, 200/206/304 and range/validator semantics, local-resource security gates, and exact unchanged Markdown rendering remain the next cumulative slices. #286 continues to own general CSS escape decoding.
- Add CacheStorage controlled fetch broker #303 — CacheStorage + controlled request broker (
Security-bound follow-up before merge: the lower and upper heads are now
0267d607/34cb18b0. Worker response consumption enforces the 64 MiB body ceiling while reading chunks, before allocating the combined result. The native gate feeds 65 logical MiB through repeated 1 MiB chunks, requiresQuotaExceededErrorpropagation to the controlled fetch, and retains the same 8 MiB heap / 64 MiB RSS ceilings.Cumulative top rerun passes: native 100-cycle p95 0.284 ms, heap 1,161,272 → 1,161,272 bytes, peak RSS 38,207,488 → 49,430,528 bytes; native candidate contract 3/3 in 67 ms. The Chrome 153 contract remains 3/3; the browser-side fixture did not change.
Rebase/status update for the visible resource-plane stack:
- Add CacheStorage controlled fetch broker #303 lower head
bd1b872eis rebased onto exact main3d143240. - Add TransformStream resource fallback #304 cumulative head
c6c26649remains based on the lower branch. - Implement effective CSS property cascade semantics #305 overlaps only the additive component-profile ledger; both rebases were conflict-free and there is no runtime/test semantic overlap.
- Focused cumulative revalidation passes: portable literal tests 2/2, extracted bootstrap syntax under packaged Node 24, snapshot/native incremental build, native WPT contract 3/3 in 69 ms, and 100 broker/stream cycles at p95 0.210 ms with stable V8 heap (1,161,232 -> 1,161,232 bytes) and peak RSS 38,207,488 -> 49,266,688 bytes.
- Chrome 153 parity remains 3/3 in 138 ms; Implement effective CSS property cascade semantics #305 does not change this contract or bootstrap byte surface.
The remaining #266 work stays open: parser/image/style request interception, HTTP 200/206/304 and range/ETag behavior, local-resource security, and exact unchanged Markdown product acceptance.
- Add CacheStorage controlled fetch broker #303 lower head
The two-entry resource-plane stack is merged in dependency order:
- Add CacheStorage controlled fetch broker #303 CacheStorage/request broker: merge commit
3a7660a0 - Add TransformStream resource fallback #304 WritableStream/TransformStream cumulative top: merge commit
50443f5b
Before merge, both branches were rebased conflict-free on #305/main
3d143240; the only shared path was the additive component-profile ledger. Focused cumulative gates passed locally (literal 2/2, extracted Node 24 syntax, snapshot/native build, native contract 3/3 in 69 ms, and 100 cycles at p95 0.210 ms with stable V8 heap and bounded RSS). The queued duplicate hosted workflows were canceled under the focused stack policy after the validated top merged.#266 remains open for parser/image/style request interception, HTTP cache/range semantics, local-resource security, and exact unchanged Markdown product acceptance.
- Add CacheStorage controlled fetch broker #303 CacheStorage/request broker: merge commit
Resource-plane progress now on
main:- Intercept connected resources through Service Workers #310 /
723dd48f: controlled dynamic connected script, stylesheet, and image resources. - Intercept parser and frame resources through service workers #319 promoted by Promote parser and frame service worker interception #321 /
d7720a63: initial parser-blocking stylesheet/script and nested-frame hydration resources, including stale-generation retirement and fail-closed handled failures. - Exact native and Chrome contracts pass; the parser/frame native stress gate completes 100 hydrate/remove cycles within its p95, heap, and RSS bounds.
#266 remains open. The next slice is the first still-missing browser-standard resource-plane contract after an exact-main audit: streams/body ownership and CacheStorage integration, followed by ranges/validators/security/product acceptance. CSS
url()interception remains separately scoped.- Intercept connected resources through Service Workers #310 /
12 remaining items
Started native child #376 from exact post-#374 main
c9079ba7for the remaining bounded offline/cache gap. Current CacheStorage entries are realm-local and disappear when an active Service Worker is replaced, so unchanged Code v6 cannot use a prior streamed/validated body when the host replies 304 after an application worker update.#376 owns only in-memory cache continuity across the same registration's active-worker replacement, with unchanged-Code/Chrome/native quota, 100-cycle, memory, and retirement gates. It adds no durable storage, mapping, filesystem/network authority, or consumer bypass. Paths are disjoint from open #375 and #76.
Resource cache continuity slice #376 completed in #378 and merged as
a759ff3a008e362708b6b281ebb7c2742921eb53.Evidence: Chrome 153 passed 5/5 replacement/cache assertions and 100 cache cycles at 1.5 ms p95. The native unchanged-Code Markdown v6 path streamed a 200 once, replaced the active worker, then served 100 validator-driven 304 reuse cycles from the retained cache with a single body stream start. Heap/RSS lifecycle bounds passed. Exact-head Linux, macOS, portable V8, and native document checks all passed.
Scope stays fail-closed: same live registration and engine-memory lifetime only; unregister/shutdown retire data; no disk, cross-engine, filesystem, origin, CSP, or network authority changed.
Owned from exact main
a759ff3a008e362708b6b281ebb7c2742921eb53onfeature/service-worker-cache-revalidation-266.Reproduction: parser speculative prefetch calls
read_resource_cachewithdigest(kind, resolved URL), while the normal loader writes and readsdigest(kind, resolved URL + initiator origin + cookie). A fresh admitted parser resource is therefore missed and re-read from the host. This matches the existing Linux sequential reuse and macOS four-engine single-flight request-count failures recorded under #266.This child owns only key parity for fresh speculative reuse plus validator/304, isolation, performance, memory, and teardown proof. Origin, cookie, resource kind, freshness, admission, credentials, host callbacks, and stale fallback remain authoritative. It adds no durable CacheStorage, cross-origin reuse, filesystem/network permission, or consumer-specific path.
Collision audit: the only open PR is consolidation #76, limited to compatibility documentation. #248 owns File System Access resolution. This slice owns the native resource cache/prefetch include, its focused native gate/filter, and a dedicated WPT-style freshness contract/profile; it excludes AppScene, CSS implementation, #76, #248, and vscode-demo.
Implemented and merged in #383 as
b5b51017ab1888ecdadbb638590afa645ee5f62a.Final scope and evidence:
- parser prefetch and normal loads now use the same resource-kind, resolved-URL, initiator-origin, and cookie partition key;
- cross-engine single-flight remains limited to credential-omitting requests or an explicitly shared compilation-cache host;
Set-Cookie, uncacheable, origin-changing, and cookie-changing responses remain engine-private; - Chrome 153 WPT-derived contract passed 3/3 in 60 ms, covering fresh reuse, validator/304 reuse, and 100 parser cycles with one network request;
- native focused gate passed 100 cycles with p95 3.90671 ms, stable V8 heap, bounded RSS, cache-policy and credential partition coverage, and teardown coverage;
- exact-head CI passed Linux X64, macOS ARM64, portable V8, NativeAOT Avalonia 11/12, and native Linux document contracts;
- NuGet packaging and postmerge tails were canceled because they are outside this focused resource-runtime slice.
No filesystem resolve, AppScene, CSS, consolidation, or vscode-demo paths changed.
Owned from exact main
b5b51017ab1888ecdadbb638590afa645ee5f62aonfeature/webview-resource-next-266.Reproduction: Chrome 153 passes the pinned unchanged Markdown v6 fixture in 1.894 s. Native
service-worker-markdown-resourcesfails at the first cache-backed streamed resource withReferenceError: __webSceneServiceWorkerGlobalControl is not defined. The bootstrap correctly removes this private host hook fromglobalThis, but the public Cache/CacheStorage methods later look it up by that deleted global name instead of using the captured closure.#385 owns only closure use plus a privacy regression assertion and exact unchanged-worker/cache gates. It preserves origin/registration partitioning, CSP, admission, status/range/validator semantics, quotas, stream/body bounds, and all filesystem/network authority.
Collision audit: open PR #384 owns CSS supports-rule files; #382 owns File System durable grants; #267/#268 own nested-document and interaction behavior; #76 owns compatibility docs. This slice owns
webscene_v8_runtime_service_workers.inc, its CacheStorage/unchanged-Markdown focused tests, and the existing cache replacement contract/profile only if needed. It excludes those active lanes, AppScene, consolidation, and vscode-demo.Completed in #387, merged as
d4dc4fc10d98edd2a8a45a2901692c614d084652.The Cache and CacheStorage methods now retain the private native control closure after bootstrap removes the temporary global hook. Product worker code cannot observe the hook, while unchanged Code OSS v6 can cache its first streamed Markdown resource and continue through replacement/validator reuse. Origin and registration partitioning, CSP, admission, quotas, range/validator behavior, stream/body bounds, and filesystem/network authority are unchanged.
Final evidence:
- unchanged Code v6 native Markdown resource gate passed; cache replacement completed 100 cycles at 0.349 ms p95 with one body stream and flat V8 heap, and CSS-image delivery completed 100 cycles at 0.199 ms p95;
- CacheStorage replacement contract passed Chrome 153 5/5 and native 5/5 while asserting the private bridge is absent from
globalThis; - native resource-plane gate passed 100 cycles at 0.133 ms p95 with flat heap; range/cache passed 100 warm cycles at 0.185 ms p95 and a 32 MiB batch in 9.92 ms;
- exact-head Linux, macOS, portable V8, NativeAOT Avalonia 11/12, and native Linux document contracts all passed;
- Keep the private CacheStorage bridge callable after worker bootstrap #385 is closed and remains natively attached to Stream and cache admitted Code OSS webview resources #266; NuGet and redundant postmerge runs were canceled.
No nested-document, interaction, File System, CSS, AppScene, consolidation, or vscode-demo paths changed.
Owned from exact main
d4dc4fc10d98edd2a8a45a2901692c614d084652onfeature/webview-resource-acceptance-266.The full pinned Markdown fixture cannot yet run natively because its first
history.replaceStatesame-window navigation is rejected before resources; #267 owns that dependency. #388 stays below navigation and owns only the remaining unchanged-worker image evidence: admitted PNG/SVG, external HTTPS fallback, missing 404, and out-of-root 401, including zero-byte/fail-closed checks and mixed 100-cycle lifetime bounds.Owned paths are
tests/WebPlatformSubset/contracts/fixtures/vscode-markdown-preview-645f29c/index.html, the Chrome contract server only if an external image endpoint is required, andexperiments/WebScene.NativeEngine.Probe/tests/native_v8_runtime_stream_fetch_tests.inc. Runtime files will change only if the exact matrix proves a generic defect.Collision audit: #267/#268 own navigation/interaction; #382 owns File System/IndexedDB; #386 owns CSSOM layer paths; #76 owns docs. This slice excludes all of them, AppScene, CSS implementation, and vscode-demo.
#388 completed via #391, merged as
1f61af570cb73f27991c2881c129854b29e3a9b7.The product-neutral Markdown image resource matrix is now qualified: admitted binary PNG/SVG decode, external HTTPS remains on the host loader, missing local resources return 404, and out-of-root requests fail closed with 401 and no bytes. Chrome 153 passed 8/8; native 100-cycle image p95 was 0.406 ms, 64 KiB delivery p95 was 0.995 ms, heap stayed flat, and RSS/teardown bounds passed. Exact-head Linux, macOS, NativeAOT 11/12, and portable V8 checks were green; test-only paths did not select native-document CI. NuGet and redundant postmerge tails were canceled.
#419 completed through #422, merged as
2f0ae98816a3450b048efb994e283ef35a55ed17from exact PR headac3923ab1219150c053d8bb90404f349b1eabc36.The new browser/native contract qualifies the complete unchanged-Code-shaped resource ancestry:
FetchEvent.clientIdresolves the navigated nestedWindowClient, its URL supplies the webview id,clients.matchAll({ includeUncontrolled: true, type: "window" })finds the outer admission owner, and a two-chunkReadableStreamscript response reaches the child without host fallback. One hundred iframe create/load/remove cycles finish with zero pending requests and only the outer client alive.Evidence:
- Chrome 153.0.8010.50: 1/1 document and 4/4 assertions passed; 100 broker requests, one live client, 8.6 ms p95.
- Native WebPlatformSubset: 1/1 document and 4/4 assertions passed in 190 ms.
- Native resource lifecycle gate: 100 requests, 2.03 ms p95, V8 heap 1,457,624 -> 1,457,624 bytes, peak RSS 86,671,360 -> 117,669,888 bytes, post-teardown current RSS 73,498,624 -> 74,448,896 bytes, and zero controlled-script host reads.
- Exact-head Linux X64, macOS ARM64, and portable V8 checks passed. NativeAOT, package, and duplicate postmerge tails were canceled after the directly related checks passed.
Current main already satisfied the reduced semantics, so this is a test/profile change and does not expand filesystem, network, origin, cache, or admission authority. It does not overlap #81/#421 or #246.
Remaining #266 acceptance is now at the product/persistence edges:
- run the packaged unchanged webview matrix after the separate Implement Worker, transferable MessagePort, and iframe contexts for Code OSS #81/Run query-bearing iframe Worker bootstrap after document fetch #421 extension-host MessagePort blocker is removed, including Markdown plus notebook, custom editor, extension detail, chat/MCP, Mermaid, Simple Browser, and release-notes assets;
- decide whether
offline/cache behaviorrequires durable cross-engine persistence. The merged CacheStorage work intentionally guarantees bounded in-memory continuity only for the same live registration; unregister and engine shutdown retire it. If durable persistence is required, it needs a separate authority-owning child and storage design.
The nested admitted-resource identity/owner/stream/retirement path itself is qualified and no longer an open #266 gap.
#266 is complete through #431, merged as
99e852a3de72e4ceb4b47745b3cbf2f957495b9d.The final #428 gate closes the representative-consumer acceptance item with the exact unchanged Code OSS
645f29cversion-6 worker. Chrome passes 11/11 across Markdown, notebook, custom editor, extension detail, Chat/MCP, Mermaid/Codicon, Simple Browser, and release-notes assets. Native passes the same worker/resource matrix, 32 concurrent 1 MiB responses, fail-closed 401/404 admission, validator-backed 64 KiB reuse over 100 requests with one streamed body, and the existing 100-cycle resource/lifecycle gates. Matrix p95 was 0.15 ms; collected V8 heap/external memory remained within 8 MiB and RSS high-water remained within 256 MiB. The refreshed hosted portable V8 contract passed at exact PR headfd9029f6.Together with the already merged #266 children, this covers Streams, FetchEvent, CacheStorage, status/range/validator behavior, localhost mapping, bounded response ownership, parser and image resources, stale generations, nested admitted-client ancestry, and retirement. No runtime change was required for the final matrix.
The unchanged worker uses CacheStorage for conditional 304 reuse and does not define host-unavailable offline fallback. Durable storage across engine shutdown is therefore outside this product resource contract; adding it later would require a separate standards and storage-authority issue. Packaged end-to-end UI acceptance remains with #264/#260 and the release owner.
Parent epic: #264. Top-level release epic: #227.
Proven gap
VS Code OSS
service-worker.jsis the mandatory broker for everywebview.asWebviewUri(...)request. It handles FetchEvent, Request/Response/Headers, Client messaging, range requests, ETag/Last-Modified, 401/404/206/304 results, streamed response chunks, CacheStorage, and localhost port mapping. It caps active host-response bodies at 32 and times unresolved requests out after 30 seconds.WebScene
b81f594chas a bounded fetch subset, but the audited native bindings contain no CacheStorage, FetchEvent, ReadableStream, WritableStream, or TransformStream implementation. Current Markdown content references extension CSS/scripts throughasWebviewUri; local images and every other webview consumer share this broker.Scope and dependencies
Acceptance
respondWith/waitUntil, and client-message transfer.vscode-demo/README.mdremains the exact primary fixture even though it has no inline image today.Proposed PR stack