)]}'
{
  "log": [
    {
      "commit": "d5a765f1089ce6d3f72300281481edf3dddff7f3",
      "tree": "d0ac47b67c6904fdb58ce81c93fce800a099d80b",
      "parents": [
        "2b92da0cf11fdf4a65f83d195a62544186047fe2"
      ],
      "author": {
        "name": "Hiroshige Hayashizaki",
        "email": "hiroshige@chromium.org",
        "time": "Fri Oct 09 23:53:32 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 09:07:26 2026"
      },
      "message": "[PermissionsPolicy] Fix Allowlist::Contains() to match opaque origins for \u0027*\u0027\n\nThis CL makes `PermissionsPolicy::Allowlist::Contains()` return true\nfor `matches_all_origins_` (`*` policies) even for opaque origins, so\nthat a wildcard allowlist \u0027*\u0027 matches all origins, including opaque\norigins (e.g. sandboxed iframes or data: URL frames).\n\nThis new behavior aligns with:\n- The spec: https://w3c.github.io/webappsec-permissions-policy/#matches\n- `FeaturePolicy::Allowlist::Contains()` before\n  https://crrev.com/c/1430588 (which moved the \u0027*\u0027 fallback after the\n  opaque origin early return)\n- `ParsedPermissionsPolicyDeclaration::Contains()`\n\nThe check order changes in this CL are:\n\n- Check `matches_all_origins_` first. This intentionally changes the\n  behavior as specified, which is covered by the added unit tests and\n  WPTs.\n- Check opaque origins before `allowed_origins_`. This doesn\u0027t change\n  the behavior, because `DoesMatchOrigin()` always returns false for\n  opaque origins.\n\nThis CL also updates\n`PermissionsPolicyTest.TestSandboxedFrameFromHeaderPolicy` to properly\npass an empty container policy, matching its comments and ASCII diagram.\n\nUnit tests in `permissions_policy_unittest.cc` (which mostly corresponds\nto the tests to be deleted in https://crrev.com/c/8464750) and WPT tests\nfor wildcard \u0027*\u0027 container policies with sandboxed and data: URL frames\nare added.\n\nThis also fixes the behavior of Worker permissions policy\n(crbug.com/562705553) around `data:` workers, as\n`PermissionsPolicy::Allowlist::Contains()` can be called e.g. from\n`ExecutionContext::IsFeatureEnabled()` from\nhttps://crrev.com/c/8426410/10/third_party/blink/renderer/core/workers/shared_worker.cc#298\n\nTAG\u003dagy\nCONV\u003dc5b4675c-907b-4a62-821b-dc605b21d806\n\nBug: 565859110, 562705553\nChange-Id: Ife867aba7e8309f499ffdce3304b288dfc50508d\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8464749\nCommit-Queue: Hiroshige Hayashizaki \u003chiroshige@chromium.org\u003e\nReviewed-by: Antonio Sartori \u003cantoniosartori@chromium.org\u003e\nReviewed-by: Daniel Vogelheim \u003cvogelheim@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1716126}\n"
    },
    {
      "commit": "2b92da0cf11fdf4a65f83d195a62544186047fe2",
      "tree": "2ccf1ad54ea35f8fa7acdad846d97dcc02ef9b55",
      "parents": [
        "84fb58b58270525a849fd852e9a70029b6b7e30b"
      ],
      "author": {
        "name": "Mahesh Kannan",
        "email": "kmaheshb@google.com",
        "time": "Fri Oct 09 23:53:20 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:55:39 2026"
      },
      "message": "[WebAudio] Test malformed AudioWorklet process() (Part 1 of 2)\n\nRename audioworkletprocessor-no-process-function.https.html to\naudioworkletprocessor-malformed-process.https.html and expand it to\ncover undefined process(), a non-callable data property (42), a getter\nreturning a non-callable value (42), and a process getter throwing an\nError.\n\nAdd a subtest that assigns process after construction and before\nrendering, verifying that process is read in the rendering loop rather\nthan at registration or construction.\n\nCheck in the trunk failure baseline to be resolved in Part 2.\n\nTAG\u003dagy\nCONV\u003da00f6083-3709-4d5a-a95e-434c28d1ecc1\n\nBug: 413259648\nTest: audioworkletprocessor-malformed-process.https.html\nChange-Id: Ica5ecafba0b76304df9a2f99506e9867e245c6a5\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8520321\nReviewed-by: Thomas Guilbert \u003ctguilbert@chromium.org\u003e\nCommit-Queue: Mahesh Kannan \u003ckmaheshb@google.com\u003e\nCr-Commit-Position: refs/heads/main@{#1716111}\n"
    },
    {
      "commit": "84fb58b58270525a849fd852e9a70029b6b7e30b",
      "tree": "5c55e1f679a5e5bef88e53621c2cb26a45ff57c7",
      "parents": [
        "4910ef70cf457f143ebb7f86198134ebd2571882"
      ],
      "author": {
        "name": "Alison Maher",
        "email": "almaher@microsoft.com",
        "time": "Fri Oct 09 23:21:35 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:55:32 2026"
      },
      "message": "[Masonry] Preserve item end margins during fragmentation\n\nGrid-lanes items include their block-end margins during initial\nplacement, but the per-fragment placement pass only used the fragment\nborder-box end. When a column item finished in a fragmentainer, this\ncould make the container fragment intrinsic block size too small and\nincorrectly carry trailing space into another fragment.\n\nPersist each resolved block-end margin in the shared item placement\ndata. Include it when the item first reaches its block end, then clear\nit so parallel-flow continuations cannot apply it again.\n\nBug: 343257585\nChange-Id: Idd1987b184dbe85f7ba5b3213cac563d753c5a1f\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8532867\nReviewed-by: Morten Stenshorne \u003cmstensho@chromium.org\u003e\nCommit-Queue: Alison Maher \u003calmaher@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1716062}\n"
    },
    {
      "commit": "4910ef70cf457f143ebb7f86198134ebd2571882",
      "tree": "e44f3b602f2b7914e35192a919fc1cfa768692f8",
      "parents": [
        "3d17e5ead7f00f8a5cb25c8574175d7a5d5ddc82"
      ],
      "author": {
        "name": "Celeste Pan",
        "email": "celestepan@microsoft.com",
        "time": "Fri Oct 09 22:45:26 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:55:24 2026"
      },
      "message": "[masonry] Fix paint order in reference\n\nThe test was failing because in the reference, the third item\u0027s text was\npainting over the fifth item\u0027s text. This change addresses the paint\norder issue.\n\nBug: 343257585\nChange-Id: Ib21d7960ba26cf450a2c6d77eeeab8252551c729\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8548915\nReviewed-by: Alison Maher \u003calmaher@microsoft.com\u003e\nCommit-Queue: Celeste Pan \u003ccelestepan@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1716054}\n"
    },
    {
      "commit": "3d17e5ead7f00f8a5cb25c8574175d7a5d5ddc82",
      "tree": "d69977195aeda4aaa91107941bec99faf39e4680",
      "parents": [
        "5cc2dd894eeb0b0cd25a3165fd872a6a5b025cac"
      ],
      "author": {
        "name": "Noam Rosenthal",
        "email": "nrosenthal@chromium.org",
        "time": "Fri Oct 09 22:45:14 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:55:17 2026"
      },
      "message": "Clean up open elements and pending scripts on HTMLStream abort and EOF\n\nAlign HTMLDocumentParser, HTMLTreeBuilder, ScriptLoader, and PendingScript with the WHATWG HTML spec for fragment parser abort and EOF:\n- On StopParsing() for fragment parsers (\u0027abort a parser\u0027, fragment case), mark open \u003cscript\u003e elements already-started, pop all open elements so elements like \u003cstyle\u003e finish parsing children, and cancel pending parser-blocking and deferred scripts.\n- At EOF in the \u0027text\u0027 insertion mode, mark an unclosed \u003cscript\u003e already-started for fragment parsers, so it never runs even if it is later connected.\n\nBug: 491743369\nChange-Id: I92f8b6e1fc762a28de590ed32ff98b3e33c6e628\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8529650\nReviewed-by: Mason Freed \u003cmasonf@chromium.org\u003e\nCommit-Queue: Noam Rosenthal \u003cnrosenthal@google.com\u003e\nCr-Commit-Position: refs/heads/main@{#1716036}\n"
    },
    {
      "commit": "5cc2dd894eeb0b0cd25a3165fd872a6a5b025cac",
      "tree": "58486a3c33d9e4d7cd72575be051f08c86493ddf",
      "parents": [
        "d9984257b41603887635b9d841ac41e3a870bd6e"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 22:09:26 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:19:38 2026"
      },
      "message": "[wpt] Make integrity-policy/style.https.html?reporting\u003dtrue fail fast\n\nWhen a policy violation is expected, the ?reporting\u003dtrue variant awaited\nthe ReportingObserver promise with no bound. Chromium only implements\nIntegrity-Policy for the script destination (IntegrityPolicyScript), so\nfor style no \u0027integrity-violation\u0027 report is ever dispatched and the\nvery first subtest hangs until the harness timeout, which is why the\nvariant has been [ Skip Timeout ] since it was imported.\n\nRace the report promise against a timer in both branches (1s when a\nreport is expected, keeping the existing 100ms when one is not). The\nstyle has already finished loading by this point, so a conforming\nimplementation still observes the report immediately, while a\nnon-conforming one now gets a deterministic per-subtest FAIL (\"Expected a\npolicy violation report\") in about a second instead of a timeout.\n\nAdd the Chromium baseline for ?reporting\u003dtrue, which mirrors the existing\n?reporting\u003dfalse baseline plus the report-only case, and drop the\n[ Skip Timeout ] expectation so the variant runs on the bots again.\n\nBug: 431034515\nChange-Id: Iaa024bc977d407cee48ba5fc25c1a55f69e391a1\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8547072\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1716020}\n"
    },
    {
      "commit": "d9984257b41603887635b9d841ac41e3a870bd6e",
      "tree": "825d85fa5c13807e06f7e95a6fb128ef3c10dac4",
      "parents": [
        "5a21b581e48eff9dc5cce62205d773cf2dbf2bf1"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Fri Oct 09 22:09:15 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:19:32 2026"
      },
      "message": "[html-in-canvas] Keep MailboxTextureBacking single-threaded\n\nIn nested html-in-canvas scenarios, GetCanvasSnapshot recorded a nested\ncanvas snapshot without first making it unaccelerated. When transferred\nto worker threads via ElementImage, a single-threaded\nMailboxTextureBacking object bound to the main thread\u0027s GPU context\ncould be used on worker threads, causing multiple threads to\nsimultaneously use the main thread\u0027s unsynchronized\nRasterContextProvider. This patch ensures GetCanvasSnapshot only draws\nan unaccelerated snapshot, similar to the non-nested case in\nHTMLCanvasElement::PaintInternal.\n\nTo harden against this issue, the existing MailboxTextureBacking thread\nchecks have been converted to CHECKS, and have been expanded.\n\nFixed: 569129173\nChange-Id: Ide09e9375da36ba55bf3dca69d5eb1d2811112c7\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8549355\nReviewed-by: Stefan Zager \u003cszager@chromium.org\u003e\nCommit-Queue: Stefan Zager \u003cszager@chromium.org\u003e\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nCommit-Queue: Philip Rogers \u003cpdr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1716006}\n"
    },
    {
      "commit": "5a21b581e48eff9dc5cce62205d773cf2dbf2bf1",
      "tree": "665b9b4cff03abe631924c94df037cc93d3758c2",
      "parents": [
        "1fb0000432983e7668ddaddd5e9fad7baec1b187"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 19:19:17 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 07:19:22 2026"
      },
      "message": "Deflake WPT COOP iframe-popup-same-origin-to-* tests\n\nIn resources/iframe-test.js:\n\n1. Run subtests sequentially with promise_test instead of\npromise_test_parallel, and clean up each subtest\u0027s iframe and popup\nvia t.add_cleanup (waiting for the popup to acknowledge before\nclosing) instead of add_completion_callback. Previously, all 6\nsubtests in a variant ran concurrently and kept all 6 iframes and 6\npopups alive polling /common/dispatcher/dispatcher.py until the entire\ntest file completed, saturating the 6-socket-per-origin HTTP/1.1 pool.\n2. In the \u0027severed\u0027 opener state with window_open, poll popup.closed in\nthe iframe up to 2.5s instead of relying on a fixed 500ms timer that\ncould race cross-process WindowProxy detachment IPC under load.\n3. Remove the obsolete unparameterized [ Skip Timeout ] entries for\niframe-popup-same-origin-to-unsafe-none.https.html and\niframe-popup-same-origin-to-same-origin.https.html, as well as the\nLinux [ Failure Pass ] entry for\niframe-popup-same-origin-to-unsafe-none.https.html?*, from\nTestExpectations.\n\nBug: 40815983, 539889938\nChange-Id: Idad1867ad8befaac0306f5834f51062f0d8b158e\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8550153\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715814}\n"
    },
    {
      "commit": "1fb0000432983e7668ddaddd5e9fad7baec1b187",
      "tree": "a2077f3d8b399374f9b11fde83c431e74d8b5e34",
      "parents": [
        "7bcd699b26b51fb7ec8f49a46bf8d6d704fff358"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 21:28:45 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 06:10:39 2026"
      },
      "message": "[COOP] Fix top navigation and expectation in navigate-top-to-aboutblank\n\nnavigate-top-to-aboutblank.https.html has been marked [ Failure ] since\nCL 2565243 switched the iframe top-navigation from sandbox to\ntest_driver.bless(). Because the iframe is inside a COOP popup window\nwith no opener reference to the main testharness window, calling\ntest_driver.bless() inside the iframe fails in both wptrunner (\u0027Tried to\nrun in a non-testharness window without a call to set_test_context\u0027) and\ncontent_shell, preventing the navigation to about:blank from ever\noccurring.\n\nFix this by setting sandbox\u003d\"allow-top-navigation allow-scripts\nallow-same-origin\" on the iframe so it can navigate top without a user\ngesture while preserving its origin. Also update the third subtest\n(opener with COOP: same-origin-allow-popups navigated to about:blank by\na cross-origin iframe) to expect expect_opener_closed \u003d true, as\nsame-origin-allow-popups only relaxes browsing context group switches\nwhen navigating from an initial empty document, not when navigating the\ntop-level document itself to COOP: unsafe-none.\n\nRemove the [ Failure ] expectation from TestExpectations.\n\nBug: 40734373\nChange-Id: Ie938eaa3fc741e0ba24eb3b22cbe44772f26eca4\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8549095\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715959}\n"
    },
    {
      "commit": "7bcd699b26b51fb7ec8f49a46bf8d6d704fff358",
      "tree": "75c21c40e769e75328cbb7fba4a9a67a2b91e8d7",
      "parents": [
        "084bc83409ed15c241773281fe39902aef9bed9e"
      ],
      "author": {
        "name": "Helmut Januschka",
        "email": "helmut@januschka.com",
        "time": "Fri Oct 09 21:28:34 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 06:10:26 2026"
      },
      "message": "Reland \"Keep wavy text decorations continuous across fragments\"\n\nThis is a reland of commit 198d0b60e4b380d9af19291d6f36813a808c675b\n\nThe original change was reverted because fast/ruby/text-decoration.html\nfailed on win11-arm64-rel-tests. It had added a win11-arm64-specific\nbaseline from a stale try run; the bot\u0027s actual output is byte-identical\nto the updated platform/win baseline. This reland drops the win11-arm64\nbaseline so the test falls back to the matching win one, and runs the\nCI-only suites on CQ via Include-Ci-Only-Tests to verify before landing.\n\nOriginal change\u0027s description:\n\u003e Keep wavy text decorations continuous across fragments\n\u003e\n\u003e Anchor the wavy pattern at the start of the decorating box instead of\n\u003e each fragment\u0027s own origin, so the wave phase no longer restarts at\n\u003e inline element boundaries like a nested \u003cem\u003e. Behind the default-on\n\u003e WavyDecorationContinuousPhase runtime feature as a kill switch.\n\u003e\n\u003e Bug: 41287729\n\u003e Change-Id: Ia6ec134cdab6bbb3d2f7f64b631bc499bd9f4a56\n\u003e Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8456548\n\u003e Commit-Queue: Helmut Januschka \u003chelmut@januschka.com\u003e\n\u003e Reviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\n\u003e Cr-Commit-Position: refs/heads/main@{#1714354}\n\nBug: 41287729\nChange-Id: I1040cb7c219339dfb27166d953417e96ddd31272\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8537549\nCommit-Queue: Helmut Januschka \u003chelmut@januschka.com\u003e\nReviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715952}\n"
    },
    {
      "commit": "084bc83409ed15c241773281fe39902aef9bed9e",
      "tree": "bdaf1bda3acf4b048e529b3467315127d73de891",
      "parents": [
        "afc65f299c72f9a2133c547af46bb9e6951acdfd"
      ],
      "author": {
        "name": "Monica Chintala",
        "email": "monicach@microsoft.com",
        "time": "Fri Oct 09 19:54:52 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 06:10:18 2026"
      },
      "message": "WebTransport: Implement WebTransport keying material export\n\nImplement the current three-argument exportKeyingMaterial() API and\nscope TLS exporter output to the WebTransport CONNECT stream. Queue\nrequests made while connecting, reject requests after closure, and\nvalidate inputs at both the Blink and network-service boundaries.\n\nThe current Web IDL requires label, context, and outputLength; calls\nwith missing arguments reject with TypeError. Construct the HTTP/3\nexporter context in Chromium\u0027s dedicated WebTransport client using\nQUICHE\u0027s span-based QuicDataWriter API so the buffer size and storage\ncannot become inconsistent.\n\nExpose the API through the generated, disabled-by-default Blink\nWebTransportExportKeyingMaterial base feature.\n\nChromeStatus: https://chromestatus.com/feature/4860330806214656\nSpec: https://www.w3.org/TR/webtransport/#dom-webtransport-exportkeyingmaterial\n\nBug: 556304550\nChange-Id: Id925aa5633c8d0ae39fc59e0630ff1b214bbe9e6\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8272125\nReviewed-by: Alison Maher \u003calmaher@microsoft.com\u003e\nReviewed-by: Adam Rice \u003cricea@chromium.org\u003e\nReviewed-by: Alex Gough \u003cajgo@chromium.org\u003e\nReviewed-by: Nidhi Jaju \u003cnidhijaju@chromium.org\u003e\nCommit-Queue: Monica Chintala \u003cmonicach@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715849}\n"
    },
    {
      "commit": "afc65f299c72f9a2133c547af46bb9e6951acdfd",
      "tree": "9a3581870567656d5a170fd801942037c31f989e",
      "parents": [
        "3d9fd1ffe7c3c7c01ca87874b2c8675a224a33b8"
      ],
      "author": {
        "name": "Dale Curtis",
        "email": "dalecurtis@chromium.org",
        "time": "Fri Oct 09 19:55:03 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 04:40:05 2026"
      },
      "message": "Preserve durations for unset or duplicate timestamps during encoding\n\nVideoEncoder previously tracked per-frame metadata in a base::flat_map\nkeyed by timestamp, defaulted unset frame durations to 0\n(base::TimeDelta()), and left DecoderBuffer duration at its default of 0\ninstead of media::kNoTimestamp when duration was zero or unset. This\ncaused input frames without a duration to produce EncodedVideoChunks\nwith duration 0 instead of null, and caused frames with duplicate or\nreordered timestamps to overwrite or misassociate metadata. Pending\nmetadata was also not cleared on reset().\n\nDefault unset frame durations to media::kNoTimestamp, store\nFrameMetadata in input order in a Vector, consume the first matching\nentry in CallOutputCallback() while evicting unmatched entries older\nthan the 16-frame reordering window, and clear pending metadata on\nreset().\n\nFixed: 561828156\nChange-Id: Ie05a8d1556a7651542c9076b71d39e3824fc7c08\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8537870\nAuto-Submit: Dale Curtis \u003cdalecurtis@chromium.org\u003e\nCommit-Queue: Eugene Zemtsov \u003ceugene@chromium.org\u003e\nReviewed-by: Eugene Zemtsov \u003ceugene@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715855}\n"
    },
    {
      "commit": "3d9fd1ffe7c3c7c01ca87874b2c8675a224a33b8",
      "tree": "10ba5774624fd365e8ff95dc61c3c8e193957a1f",
      "parents": [
        "1f35f82c8971d10d14d40d9963b090d0e6ca36b0"
      ],
      "author": {
        "name": "Timothy Nikkel",
        "email": "tnikkel@gmail.com",
        "time": "Fri Oct 09 18:35:16 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 03:10:59 2026"
      },
      "message": "Add WPT reftests for JXL images with premultiplied alpha.\n\nPremultiplied and non-premultiplied versions of the same RGB and gray grids,\neach compared against one PNG, plus the conformance suite\u0027s\nalpha_premultiplied image compared against its reference PNG. cjxl\n--premultiply\u003d1 only marks the pixels as premultiplied, so the premultiplied\ngrids are encoded from PNGs that were premultiplied first.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331952\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2079663\ngecko-commit: 895ec42d7aba4b99ec2245a79cb59c5dda8d3c1b\ngecko-commit-git: d6ba1a3081a9b04e71e8691d72c9a5cdb2263c10\ngecko-reviewers: saschanaz\n"
    },
    {
      "commit": "1f35f82c8971d10d14d40d9963b090d0e6ca36b0",
      "tree": "ddc5f8a89ba1828ef35113610552e84f7622b06c",
      "parents": [
        "f6e6e1fbe25c2a025ff6e6fb82db2da18e406c3c"
      ],
      "author": {
        "name": "Emilio Cobos Álvarez",
        "email": "emilio@crisal.io",
        "time": "Fri Oct 09 18:45:20 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 03:10:01 2026"
      },
      "message": "r\u003dlayout-reviewers,dshin\n\nDifferential Revision: https://phabricator.services.mozilla.com/D332254\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2078981\ngecko-commit: 4cc7c4149056b7c9791a3a04afc497f569533972\ngecko-commit-git: 6272e5372f6132fa52d0dcaa6dc6680ac5c6fbcc\n"
    },
    {
      "commit": "f6e6e1fbe25c2a025ff6e6fb82db2da18e406c3c",
      "tree": "2afc794469ca9f215bb70829c2b934901478939d",
      "parents": [
        "6469f84646192e2d9413becb9da9267a061064e3"
      ],
      "author": {
        "name": "Byron Campen",
        "email": "docfaraday@gmail.com",
        "time": "Fri Oct 09 18:18:49 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 03:07:40 2026"
      },
      "message": "Add copy/clone tests for buffers from a separate window.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D328169\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2073653\ngecko-commit: 284f376d132141bb4584b4cc2a972a1e473e72b5\ngecko-commit-git: df2c26d15da8532451195e86e6e20e852fe6baed\ngecko-reviewers: ng, sfink\n"
    },
    {
      "commit": "6469f84646192e2d9413becb9da9267a061064e3",
      "tree": "a57fb9af8d9fe8ff7f3af0bbafcbedc1aa00e710",
      "parents": [
        "23299cbccf7baf44b0ea73ce4af8549b355958e1"
      ],
      "author": {
        "name": "Rich",
        "email": "raw@goodhumans.net",
        "time": "Fri Oct 09 18:48:08 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 03:01:44 2026"
      },
      "message": "Bug 2052601 - Context-aware word boundary check for text-fragments\n\nPrior to this change, the code used only 2 surrounding characters to check for a word boundary. In many cases, this does not provide enough context to the segmenter to make correct determinations of word boundaries. This patch adds a mSegmenterWordBoundaries nsFind option that collects the text in the entire block the text node falls in and then uses the WordBreakIterator to find all of the word boundaries within the block. Checks for boundaries are then run against that cache. The new option is exposed on nsIFind to make it testable from mochitest and available for regular find.\n\nThe SegmenterWordBoundaries option is set in the construction of both the finder (TextDirectiveFinder) and the generator (TextDirectiveCreator) so that text directive resolution and generation make use of the new word boundary detection by default. The patch does not set the new option for the general find-in-page case or change the prior behavior with the option unset.\n\nThe patch also changes test_nsFind.html so that most tests are run for both backwards and forwards searching. Additionally, it adds several new tests for complex word boundaries and the new option. Other text-directive tests are added to the wpt find-range-from-text-directive that test some scenarios the unpatched code didn\u0027t support.\n\nAn additional test was added to test_text-fragments-create-text-directive.html covering a CJK selection that also occurs as part of a longer word, which requires the generator to add context to disambiguate.\n\nThis change also fixes the boundary check at the start of nodes (bug 2052601) since the context collection extends beyond the text node back to the beginning of the block.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D310555\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2052604\ngecko-commit: 3fce8e102deb1ed096cc6299114e1be1bc399190\ngecko-commit-git: d841ac2676d99234669516049cfbe76b13f805e5\ngecko-reviewers: jjaschke\n"
    },
    {
      "commit": "23299cbccf7baf44b0ea73ce4af8549b355958e1",
      "tree": "066423b20a68edc3be6de6e130dd737ea927177a",
      "parents": [
        "e131722122caf6b3649c01120fb29e32da53a42c"
      ],
      "author": {
        "name": "Andreas Farre",
        "email": "farre@mozilla.com",
        "time": "Fri Oct 09 18:21:28 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 03:00:04 2026"
      },
      "message": "Only send previous entry on same-origin traversals.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331226\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2077842\ngecko-commit: e85207da75230d77f78258bd3d58af762fe32493\ngecko-commit-git: b14590cc776c08e55922947ae4e8bf9ab4e44f19\ngecko-reviewers: dom-core-reviewers, smaug\n"
    },
    {
      "commit": "e131722122caf6b3649c01120fb29e32da53a42c",
      "tree": "ba3f0f40b3606ca3ac3f28bbfdedb901ef95e60f",
      "parents": [
        "49692c66145b38c42b762de2236e30a8fc97ce6d"
      ],
      "author": {
        "name": "John Jansen",
        "email": "johnjansen@microsoft.com",
        "time": "Fri Oct 09 19:19:28 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:55:07 2026"
      },
      "message": "[WPT] Fix img-sizes-auto test to use attribute selector\n\nThe test\u0027s \"!important\" subtest compares a real \u003cimg sizes\u003dauto\nclass\u003dtest-important\u003e element against a synthetic \"expected\" clone\ncreated via createElementNS() in a non-HTML namespace.\n\nThe test\u0027s author rule `img.test-important { contain-intrinsic-size:\n30px 15px }` was meant to apply to that expected clone so the ref\u0027s\ncomputed style reflects the author-overridden value. Due to a Chromium\nbug (https://issues.chromium.org/issues/41276987), the class selector\nfails to match elements created in a non-HTML namespace, so the rule\nnever applied to the expected clone and the subtest compared against the\nwrong reference value.\n\nSwitch to the equivalent attribute selector\n`img[class~\u003d\"test-important\"]`, which is not affected by this bug and\nmatches the expected clone correctly, so the subtest asserts against the\ncorrect reference value.\n\nBug: 571158508\nTest: Ran run_web_tests.py for img-sizes-auto.html; manually verified all 24 subtests pass in Firefox.\nChange-Id: Ia7a8d8fbff0a4515ec99370a4fa933f90a00b7ff\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8539079\nCommit-Queue: John Jansen \u003cjohnjansen@microsoft.com\u003e\nReviewed-by: Mike Jackson \u003cmjackson@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715829}\n"
    },
    {
      "commit": "49692c66145b38c42b762de2236e30a8fc97ce6d",
      "tree": "d8f1a3dba27407a618ec36bce83f28781d07092f",
      "parents": [
        "dd8f1fc24a4a1bb61decf449c7da8704b67a4db9"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 19:19:06 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:54:57 2026"
      },
      "message": "[wpt] Fix guaranteed timeout in COOP access-reporting/reporting-observer\n\nThe last subtest (\"Access from cross-site iframe\") expects *no*\ncoop-access-violation report and calls `receive(this_window_token, 2000)`\nexpecting it to resolve with \"timeout\". However, dispatcher.js\u0027s\n`receive()` only takes a uuid and polls the dispatcher forever; the 2000\nis silently ignored. Because Chromium correctly never dispatches a report\nhere, the subtest can never complete and the whole test always hits the\nharness timeout (150s in Debug) and gets its content_shell killed.\n\nUse the directory\u0027s existing `receiveReport()` helper from\nreporting-common.js instead, which races the dispatcher against a 3s\nstep_timeout and returns \"timeout\" when nothing arrives, so the subtest\ncompletes in a few seconds. The test now passes deterministically on\nLinux, so drop the [ Pass Timeout ] expectation.\n\nBug: 40180286\nChange-Id: Ia92e732d80c25b46e66d8520b5e9b7b67d14ebe0\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8547071\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715811}\n"
    },
    {
      "commit": "dd8f1fc24a4a1bb61decf449c7da8704b67a4db9",
      "tree": "4b3d190fb0bbe6b4c5c1fe141c8940769d684b3f",
      "parents": [
        "054a941a8e1d87613e173c8d74bfb1adae9d9091"
      ],
      "author": {
        "name": "Javier Contreras",
        "email": "javiercon@microsoft.com",
        "time": "Fri Oct 09 19:18:55 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:54:51 2026"
      },
      "message": "[masonry] Test per-segment rule visibility\n\nThe CSSWG resolved that rule visibility applies per segment in grid\nlanes. Our current implementation uses whole-lane occupancy, which can\nleave rules visible beside empty portions of a lane.\n\nMost of the coverage we had was with `rule-break: none`, which is not\naffected by the resolution. So this CL adds coverage for `rule-break:\nintersection`, and converts a test we had for `none` to be for\n`intersection`. These are marked as failing, the implementation CL will\nfollow.\n\nhttps://github.com/w3c/csswg-drafts/issues/14489.\n\nBug: 343257585\nChange-Id: Ia16e07c5c58479ca2742faf05c66fc2a6dce8c57\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8496106\nCommit-Queue: Javier Contreras \u003cjaviercon@microsoft.com\u003e\nReviewed-by: Alison Maher \u003calmaher@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715798}\n"
    },
    {
      "commit": "054a941a8e1d87613e173c8d74bfb1adae9d9091",
      "tree": "9774739e5125b59ce38c16a867e96fcdd74dde6f",
      "parents": [
        "c0f453e5ef5e3b4d468a11c734acbe1167fce27d"
      ],
      "author": {
        "name": "David Awogbemila",
        "email": "awogbemila@chromium.org",
        "time": "Fri Oct 09 19:18:45 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:54:42 2026"
      },
      "message": "Do not paint focus ring for display-locked \u003carea\u003e elements\n\nWhen painting an \u003cimg\u003e with an associated focused \u003carea\u003e element,\nImagePainter::PaintAreaElementFocusRing calls EnsureComputedStyle() on\nthe \u003carea\u003e to check for outlines.\n\nIn the linked bug, Blink attempts to paint a display-locked \u003carea\u003e\nelement. This triggers a style update mid-paint which leads to a\nuse-after-free.\n\nThis CL skips painting the focus ring if the \u003carea\u003e is display-locked.\n\nBug: 570743446\nChange-Id: I6c2677fce30feb1e4a46e901a69c02084159c8b0\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8551233\nReviewed-by: Vladimir Levin \u003cvmpstr@chromium.org\u003e\nCommit-Queue: David A \u003cawogbemila@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715794}\n"
    },
    {
      "commit": "c0f453e5ef5e3b4d468a11c734acbe1167fce27d",
      "tree": "e296e17737673f2100b2070a60c450b0d2cfba14",
      "parents": [
        "bcfb7996295b002bf8fc3f475594a47cd7c5c6c2"
      ],
      "author": {
        "name": "Rune Lillesveen",
        "email": "futhark@chromium.org",
        "time": "Fri Oct 09 19:18:23 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:54:32 2026"
      },
      "message": "Let CSSParser::ParseFont() parse the shorthand directly\n\nThis drops support for CSS wide keywords and pending substitution\nvalues, which were already being dropped after parsing.\n\nAvoids arbitrary declaration parsing in @supports which may access\ncross thread access to static Persistent in GetUACounterStyleMap().\n\nThis fixes a UAF issue when the singleton was created on an off-main\nthread and later accessed from the main thread.\n\nBug: 568832157\nChange-Id: I8793cee34fc032c43918599acc52f65a5ed1c039\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8525429\nCommit-Queue: Rune Lillesveen \u003cfuthark@chromium.org\u003e\nReviewed-by: Kevin Babbitt \u003ckbabbitt@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715776}\n"
    },
    {
      "commit": "bcfb7996295b002bf8fc3f475594a47cd7c5c6c2",
      "tree": "9f94fbb283460c93221e8af7761cecb9e20a5c94",
      "parents": [
        "91a04631ef17ee6648110bddf8fe7b60e4ef5d9c"
      ],
      "author": {
        "name": "Noam Rosenthal",
        "email": "nrosenthal@chromium.org",
        "time": "Fri Oct 09 19:18:11 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:54:25 2026"
      },
      "message": "Flush pending text at the end of each chunk for HTMLStream\n\nFlush pending text (including kTextMode) at the end of each chunk and before StopParsing() for fragment parsers, so written text is in the DOM when write() resolves and no text is left buffered in HTMLConstructionSite when a writer is dropped, aborted, or its write() rejects.\n\nFixed: 568820698\nChange-Id: I79c3302e2dd8a2f2999dfdda0f30019a18d0544e\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8529649\nCommit-Queue: Noam Rosenthal \u003cnrosenthal@google.com\u003e\nReviewed-by: Mason Freed \u003cmasonf@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715746}\n"
    },
    {
      "commit": "91a04631ef17ee6648110bddf8fe7b60e4ef5d9c",
      "tree": "70d596b643bc1377fe6226e000e4c80b385fc2b6",
      "parents": [
        "7a709316772e1b77909ba484efbdaa64844f5e17"
      ],
      "author": {
        "name": "Noam Rosenthal",
        "email": "nrosenthal@chromium.org",
        "time": "Fri Oct 09 19:17:59 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 02:54:17 2026"
      },
      "message": "Handle displaced reference node and stop parsing on write error in HTMLStream\n\nWhen the reference node (next_child) is removed or moved out of its\nexpected parent mid-chunk (e.g. by a streamed inline script), drop\nsubsequent nodes, text, and foster-parented children instead of hitting\na DCHECK in ContainerNode::ParserInsertBefore or appending to the old\nparent.\n\nAlso call parser_-\u003eStopParsing() in HTMLSink::write before throwing on\nchunk string conversion failure or a displaced reference node, matching\nthe spec\u0027s writeSteps abort behavior.\n\nBug: 491743369\nChange-Id: If4bd1f1b6aa1c9fbd1ca7040899131815102bda2\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8498307\nCommit-Queue: Noam Rosenthal \u003cnrosenthal@google.com\u003e\nReviewed-by: Mason Freed \u003cmasonf@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715744}\n"
    },
    {
      "commit": "7a709316772e1b77909ba484efbdaa64844f5e17",
      "tree": "6e951756d5c309cc28703698cc4b1b33b693c693",
      "parents": [
        "b9b2c25740d6f7320e19338b2c57f07fbd91ebc2"
      ],
      "author": {
        "name": "Emilio Cobos Álvarez",
        "email": "emilio@crisal.io",
        "time": "Fri Oct 09 18:40:45 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 02:45:41 2026"
      },
      "message": "Prevent display contents pseudo-elements from showing up in SVG subtrees.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D332245\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2079938\ngecko-commit: ada9aff668bcab2f2a8f4d0bdeee200013d482e3\ngecko-commit-git: a12d1f77df06229fbcf34aaffa835bae800ecf00\ngecko-reviewers: layout-reviewers, dshin\n"
    },
    {
      "commit": "b9b2c25740d6f7320e19338b2c57f07fbd91ebc2",
      "tree": "3b81ce1edccffa175db515655b728d89a01d0933",
      "parents": [
        "c02dbf03f1aa1f1cd45ac7a780adcbcce957affc"
      ],
      "author": {
        "name": "YohYamasaki",
        "email": "y.yamasaki@tuta.com",
        "time": "Fri Oct 09 18:27:04 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 02:45:29 2026"
      },
      "message": "Scale feDisplacementMap displacement independently along each axis.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331934\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2079286\ngecko-commit: 0c46a99e610994a1cb66a5e6898b4c8543034674\ngecko-commit-git: 7f328610430f70a731e9aa13e38936b617d1797f\ngecko-reviewers: firefox-svg-reviewers, gfx-reviewers, lsalzman, longsonr\n"
    },
    {
      "commit": "c02dbf03f1aa1f1cd45ac7a780adcbcce957affc",
      "tree": "e82654a17d788faed1c50f420edbddc00f8e7181",
      "parents": [
        "c0aad05975c9d3a25e03203057682dc80fad695e"
      ],
      "author": {
        "name": "Kagami Sascha Rosylight",
        "email": "krosylight@proton.me",
        "time": "Fri Oct 09 18:16:20 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Sat Oct 10 02:40:55 2026"
      },
      "message": "Wrap value in TransformerAlgorithmsWrapper::TransformCallback\n\nThis also saves per-implementation init of JSAPI.\n\nThis also changes CompressionStream, but it\u0027s not affected as it uses bindgen function that knows better how to deal with JS values.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D328883\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2073685\ngecko-commit: 22018e93ef47f0f4409a068b69f5ecefb9f6e425\ngecko-commit-git: 671c6f648c03a658fda1b089189f4e0d9122ef0c\ngecko-reviewers: mgaudet\n"
    },
    {
      "commit": "c0aad05975c9d3a25e03203057682dc80fad695e",
      "tree": "7b1f3e704a734ce5a6203cff224ce35417f891fa",
      "parents": [
        "dbb5468a70bbd3d64600cff8915b116d289d4954"
      ],
      "author": {
        "name": "fantasai",
        "email": "fantasai.bugs@inkedblade.net",
        "time": "Fri Oct 09 19:01:55 2026"
      },
      "committer": {
        "name": "fantasai",
        "email": "fantasai.bugs@inkedblade.net",
        "time": "Sat Oct 10 02:21:11 2026"
      },
      "message": "[css-text-3] Fix test metadata\n"
    },
    {
      "commit": "dbb5468a70bbd3d64600cff8915b116d289d4954",
      "tree": "dcb5dff022dd37ea87d473a9ff9aac1eeb4c7cd9",
      "parents": [
        "b525d59a7ac82e619640d97ff49e6cc8ff973f39"
      ],
      "author": {
        "name": "Adam Rice",
        "email": "ricea@chromium.org",
        "time": "Fri Oct 09 17:22:52 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 01:42:13 2026"
      },
      "message": "Set WebSocketCommon state to kClosed when WebSocketStream aborts\n\nWhen WebSocketStream::OnAbort() cancelled the handshake and reset\nchannel_ to nullptr, it left common_ in the kConnecting state. Calling\nclose() afterwards passed a null channel_ to\nWebSocketCommon::CloseInternal() while in kConnecting, causing a null\npointer dereference in WebSocketChannelImpl::Fail().\n\nSimilarly, when WebSocketStream::Connect() returned early due to an\nalready-aborted signal, common_ remained in kConnecting and channel_ was\nnot cleared, keeping HasPendingActivity() true and causing subsequent\nclose() calls to fail an unconnected channel.\n\nSet common_ to kClosed and clear channel_ in both abort paths, and clear\nchannel_ and abort_handle_ when Connect() fails asynchronously.\n\nFixed: 432920899\nChange-Id: I2a827bba93ee1aa7e1743b2b28c9a0654478a315\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8522181\nReviewed-by: Nidhi Jaju \u003cnidhijaju@chromium.org\u003e\nCommit-Queue: Adam Rice \u003cricea@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715697}\n"
    },
    {
      "commit": "b525d59a7ac82e619640d97ff49e6cc8ff973f39",
      "tree": "c67dc8e9c51b867a17e6af213e094b71bd8c8843",
      "parents": [
        "c8482945c1e2209f9668c3acf33908979fe54ff0"
      ],
      "author": {
        "name": "Morten Stenshorne",
        "email": "mstensho@chromium.org",
        "time": "Fri Oct 09 17:22:40 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 01:42:07 2026"
      },
      "message": "[FragmentedOofInCb] Relayout self-collapsed on BFC block-offset change.\n\nInside block fragmentation, if there are any OOFs inside a\nself-collapsing block whose initial BFC block-offset estimate was wrong,\nwe need to relayout, just like we already do for adjoining floats. This\nis not an issue for non-FragmentedOofInCb, since then all OOF layout is\ndelayed until right before finishing layout of the outermost\nfragmentation context root.\n\nThe two tests included would fail when run as\nvirtual/fragmented-oof-in-cb/.\n\nBug: 40267498\nChange-Id: I8b8c170084d43c7e2630443d72ead99e83a25ebe\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8548955\nReviewed-by: Ian Kilpatrick \u003cikilpatrick@chromium.org\u003e\nCommit-Queue: Morten Stenshorne \u003cmstensho@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715696}\n"
    },
    {
      "commit": "c8482945c1e2209f9668c3acf33908979fe54ff0",
      "tree": "06416bcaa5d4a235d20b16370449ec67f2ad4b74",
      "parents": [
        "d86e829895c95cb931038cda4e24968108f7d09c"
      ],
      "author": {
        "name": "Alison Maher",
        "email": "almaher@microsoft.com",
        "time": "Fri Oct 09 16:51:50 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 01:41:59 2026"
      },
      "message": "[Masonry] Fragment nested dense-packed items\n\nFragmented grid-lanes iteration previously walked only each lane\u0027s root\nitem vector. Items stored above another item by dense packing were\nskipped, and spanners whose entries had different nested paths in each\nlane could not be resumed consistently.\n\nUse lane-local item index paths to walk nested storage in physical\nstacking order. Normal columns and rows visit dense children before\ntheir parent, while fill-reverse columns visit the recursively reversed\nparent first.\n\nBug: 343257585\nChange-Id: I7f25d568b0c375220ea0f3ceba09f9bd9471118d\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8527177\nReviewed-by: Morten Stenshorne \u003cmstensho@chromium.org\u003e\nCommit-Queue: Alison Maher \u003calmaher@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715671}\n"
    },
    {
      "commit": "d86e829895c95cb931038cda4e24968108f7d09c",
      "tree": "56bdc144b25f263a5097dd3243694e2368beba9b",
      "parents": [
        "9f868fd730423a984c45f32e6d524db9da9e21a5"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Fri Oct 09 15:49:27 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 01:41:49 2026"
      },
      "message": "Deflake html5-tree/dynamic-href-001.html by waiting for Ahem\n\n`wpt/mathml/relations/html5-tree/dynamic-href-001.html` is flaky due to\nnot waiting for Ahem to load. When the test is run by itself, the\nflakiness is consistently reproducible without this patch and goes away\nwith this fix, which waits for the font to be ready.\n\nBug: 568337130\nChange-Id: I32438cc59ade149082fb889b620ae42173356c9f\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8541197\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nCommit-Queue: Philip Rogers \u003cpdr@chromium.org\u003e\nReviewed-by: Frédéric Wang Nélar \u003cfwang@igalia.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715548}\n"
    },
    {
      "commit": "9f868fd730423a984c45f32e6d524db9da9e21a5",
      "tree": "67949d6b6baa3758437cfb64170ace4d5fac1fcf",
      "parents": [
        "521d168d63dbd206ea7fbe0b74ddd5760e6e668e"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 14:19:30 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Sat Oct 10 01:04:15 2026"
      },
      "message": "[wpt] sttf: don\u0027t assume text fragment scrolls within 2 frames\n\nThe scroll-to-text-fragment-security-replacestate target page reports\nits scroll position two animation frames after load. Blink may\nlegitimately defer processing a cross-document text fragment until the\nbrowser confirms the browsing context group state\n(NotifyRelatedPagesFinalized, sent after DidCommit is processed) or\nuntil the newly opened popup\u0027s page visibility and layout lifecycle\nsettle, and the spec allows UAs to delay the search. On a busy bot this\noccasionally lands after the 2-rAF measurement, so the noopener \u0027sanity\u0027\nsubtests flakily observe scrollY\u003d0 and fail with \u0027Expected text fragment\ndirective to activate with noopener, but got scrollPosition\u003dtop\u0027.\n\nPoll the scroll position across up to 10 animation frames before\nreporting scrollY\u003d0 instead of sampling at a fixed 2-frame point.\nPositive cases report on the exact frame the scroll lands; the \u0027must not\nactivate\u0027 cases now wait 10 frames before reporting, which also makes\nthem a stronger check. Remove the Failure Pass expectation.\n\nBug: 552768634\nChange-Id: I3a0c9d6220352b7ef2c076c5e9e32a6ca0831625\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8542876\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCommit-Queue: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715498}\n"
    },
    {
      "commit": "521d168d63dbd206ea7fbe0b74ddd5760e6e668e",
      "tree": "ebf87f05fdd0294516ec324f0c1426264f2db728",
      "parents": [
        "e779fd61e08ec7b11462cc160bae1ff263cb81f9"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 12:33:28 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 22:08:11 2026"
      },
      "message": "[wpt] Make clear-cache.https.html deterministic\n\nThe cache-clearing subtests compare random per-response tokens (uuid4\nstrings / random PNG dimensions). When a subtest fails,\nassert_not_equals embeds the token in its failure message, so the\nbaseline could never match and the test was marked \u0027[ Failure ]  # Flaky\noutput\u0027.\n\nAdditionally, clear-cache.https.html runs 13 sequential promise_tests\nthat open 32 popups sequentially (~8.3s), which previously caused it to\nalso time out against the 6s default timeout on Linux, Win, and Mac bots\n(it was marked \u0027[ Failure Timeout ]  # Flaky output\u0027 on those platforms\nbefore https://crrev.com/c/7910841 consolidated the platform lines).\n\nAssert on the equality result instead so the failure message is stable,\nadd \u003cmeta name\u003d\"timeout\" content\u003d\"long\"\u003e, update the baseline, and drop\nthe flaky-output expectation lines.\n\nThe three Image/CSS/JS subtests still fail deterministically:\nClear-Site- Data: \u0027cache\u0027 clears the HTTP cache but does not evict the\nrenderer\u0027s in-process MemoryCache for the cleared origin, so same-origin\npopups keep reusing the cached resources (the fetch()-based subtests\npass because fetch() bypasses the MemoryCache).\n\nBug: none\nChange-Id: Ifd25b85f4c3dea88161cb1cd627008ee12336dff\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8544790\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715436}\n"
    },
    {
      "commit": "e779fd61e08ec7b11462cc160bae1ff263cb81f9",
      "tree": "e4a1f49e855d4fa805be4d393ee14ac20dcce81b",
      "parents": [
        "b69fbe9e40d48c3193a133bcb3aa6b8c2df0d571"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 12:33:16 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 22:08:03 2026"
      },
      "message": "[wpt] Make clear-site-data/executionContexts test fail fast\n\nexecutionContexts.sub.html waits unconditionally for an iframe to be\nreloaded by a \u0027Clear-Site-Data: \"executionContexts\"\u0027 response. Chromium\ndoes not implement the \u0027executionContexts\u0027 type (it is ignored with an\n\u0027Unrecognized type\u0027 console warning, and \u0027*\u0027 does not include it), and\nneither does any other shipping engine: Firefox removed it, and\nw3c/webappsec-clear-site-data#59 proposes dropping it from the spec. The\ntest therefore always runs into the harness timeout (and a content_shell\nkill) on every bot.\n\nBound each wait with test.step_timeout(1000) so unsupported\nimplementations produce a deterministic per-subtest FAIL in a few\nseconds, only start the clock once the response carrying the header has\nbeen received, remove each subtest\u0027s iframe on cleanup so a late message\ncannot leak into the next subtest, mark the test as timeout\u003dlong so the\ntwo sequential negative waits have ample headroom on slow bots, and drop\nthe no-op assert_true(true) calls. Add the Chromium baseline and remove\nthe [ Timeout ] expectation.\n\nBug: crbug.com/40475877\nChange-Id: I73c2a4794c6a209f59122851b01796df3740c4d7\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8544830\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715435}\n"
    },
    {
      "commit": "b69fbe9e40d48c3193a133bcb3aa6b8c2df0d571",
      "tree": "e50d72f8c87f015c86b848909915820120fba621",
      "parents": [
        "6471ef0635a21c6d482c1eb4880f011b08c187f6"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Fri Oct 09 12:33:05 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 21:27:34 2026"
      },
      "message": "[wpt] Mark scroll-to-text-fragment-security.sub.html as timeout\u003dlong\n\nThe test opens five popups/iframes to a cross-origin (or noopener)\ntarget page, each of which requires spawning a new renderer process,\nloading the page, waiting two animation frames and round-tripping\nresults through the WPT stash. Locally this takes a steady ~4s against\nthe 6s default timeout, so it intermittently times out on loaded bots.\nSibling tests using the same pattern (scroll-to-text-fragment.html,\nscroll-to-text-fragment-security-replacestate.sub.html) already declare\n\ntimeout\u003dlong; do the same here and drop the flaky-timeout expectation.\n\nBug: 40818984\nChange-Id: I1c445ffda4f0c2a8ce23b538d31c5e9401b67a23\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8544211\nCommit-Queue: Ari Chivukula \u003carichiv@chromium.org\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nReviewed-by: Ari Chivukula \u003carichiv@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715434}\n"
    },
    {
      "commit": "6471ef0635a21c6d482c1eb4880f011b08c187f6",
      "tree": "74649ca454674a005c0cbdf943327f81bfd6a62c",
      "parents": [
        "3b8aed1e7cd75850921d452b7d9a3e5c59cb5ac0"
      ],
      "author": {
        "name": "Maksim Sadym",
        "email": "sadym@chromium.org",
        "time": "Fri Oct 09 10:55:12 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 19:17:25 2026"
      },
      "message": "[chromium-bidi] Serialize input.releaseActions on the actions queue\n\n- Serialize parallel input.performActions and input.releaseActions\n  commands on the top-level browsing context\u0027s actions queue, and relax\n  the WPT parallel pointer test to accept any integer detail on\n  mousemove.\n- Previously, input.releaseActions bypassed the actions queue and\n  deleted the InputState instance along with its mutex, while\n  input.performActions mutated input state before entering the queue,\n  causing pipelined commands to race and drop release events.\n- Build action ticks and dispatch release actions inside the top-level\n  InputState queue, and reset active input sources and cancel actions in\n  place while preserving the queue mutex.\n\nBug: 411434092\nCq-Include-Trybots: luci.chromium.try:linux-webdriver-bidi-rel\nInclude-Ci-Only-Tests: chromium.linux:Linux Tests|webdriver_wpt_tests\nChange-Id: I674f9899ba35afa1585edaf7ffd22c7a5dd436fd\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8538847\nReviewed-by: Nikolay Vitkov \u003cnvitkov@chromium.org\u003e\nCommit-Queue: Nikolay Vitkov \u003cnvitkov@chromium.org\u003e\nAuto-Submit: Maksim Sadym \u003csadym@chromium.org\u003e\nCommit-Queue: Maksim Sadym \u003csadym@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715405}\n"
    },
    {
      "commit": "3b8aed1e7cd75850921d452b7d9a3e5c59cb5ac0",
      "tree": "ff120257c89267abb2067839345f35b6957c0826",
      "parents": [
        "1c54118ac3bc08bc4292d14da0cc8daea302fd07"
      ],
      "author": {
        "name": "Christian Biesinger",
        "email": "cbiesinger@chromium.org",
        "time": "Fri Oct 09 17:50:28 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 17:50:28 2026"
      },
      "message": "Make encrypt_after_connect support work (#40709)\n\n* Make the HTTP server also act as an HTTPS proxy\n\nEnable encrypt_after_connect on the plain HTTP server when SSL is\navailable, so that a PAC file can route https:// requests through it.\nAlways compute an SSL config when certificates are available, even if\nthe SSL environment is not otherwise enabled.\n\nAlso pass the CA certificate path for the pregenerated certificates so\nthat an SSL config is produced by default, and fall back to plain HTTP\nin start_http_server when there is no SSL config.\n\nExtend infrastructure/server/test-pac to cover an https:// request\nthrough the proxy.\n\nCo-Authored-By: Claude Opus 5.5 (1M context) \u003cnoreply@anthropic.com\u003e\n\n* Clean up wptserve\u0027s handling of connections encrypted after CONNECT\n\nClose TLS connections set up after a CONNECT request in finish(),\nsending a close_notify first. socketserver only closes the socket it\naccepted, which wrap_socket() detaches, so the TLS socket was left\nopen. This replaces shutting down every connection that is marked to\nbe closed, which ended TLS connections without a close_notify.\n\nTrack the scheme per connection, so that requests sent through a\nCONNECT tunnel have an https URL instead of the HTTP server\u0027s scheme.\n\nExplain why the connection is kept open after a CONNECT request.\n\nCo-Authored-By: Claude Opus 5.5 (1M context) \u003cnoreply@anthropic.com\u003e\n\n---------\n\nCo-authored-by: Claude Opus 5.5 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "1c54118ac3bc08bc4292d14da0cc8daea302fd07",
      "tree": "caf960fc3ad0dcbec6ac2593baeb9682b05ddfe8",
      "parents": [
        "dcdb122e7425b76d3a1f7d477639115c16669646"
      ],
      "author": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Wed Sep 30 08:33:59 2026"
      },
      "committer": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Fri Oct 09 17:27:45 2026"
      },
      "message": "Fix and extend cross-origin WebAssembly.Module sharing tests\n\nSame-site documents share an agent cluster unless they are origin-keyed, and\nthe WebAssembly Web API only rejects a WebAssembly.Module whose agent cluster\ndiffers from the target\u0027s. Documents in non-secure contexts, which most of\nthese tests use, cannot be origin-keyed.\n\ncross-origin-module-sharing-fails.html used OTHER_ORIGIN for its \"different\nagent cluster\" subtest, but that origin is same site. Use\nHTTP_NOTSAMESITE_ORIGIN instead. Its HTTPS_ORIGIN subtest claimed the same\nagent cluster, but the scheme makes that origin a different site, so describe\nit accurately. Also cover a sandboxed iframe, whose opaque origin is only same\nsite with itself, and rename the test to window-cross-site-failure.html.\n\nshare-module-cross-origin-fails.sub.html expected sharing with a same-site\ncross-origin document to fail, contradicting\nwindow-similar-but-cross-origin-success.sub.html. That restriction is proposed\nin https://github.com/WebAssembly/spec/issues/1303 but is not part of the\nWebAssembly Web API. Replace it with window-same-site-success.sub.html, which\nexpects sharing with iframes on another host and on another port to succeed,\nwithout using document.domain.\n\nAdd window-cross-origin-isolated.https.sub.html. Cross-origin isolation keys\nagent clusters by origin, so sharing with a same-site cross-origin iframe fails\nthere while sharing with a same-origin iframe succeeds.\n"
    },
    {
      "commit": "dcdb122e7425b76d3a1f7d477639115c16669646",
      "tree": "5ce629ea28cfd32d74803fe99ff9b66b77d17488",
      "parents": [
        "0c8e6e9999057f167da1947a1bea58b08348c4b3"
      ],
      "author": {
        "name": "Ahmad Saleem",
        "email": "52317531+Ahmad-S792@users.noreply.github.com",
        "time": "Fri Oct 09 16:43:49 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 16:43:49 2026"
      },
      "message": "Module script elements with an empty or invalid src fire the error event synchronously (#63455)\n\nThis patch aligns WebKit with Gecko / Firefox and Blink / Chromium.\n\n\"Prepare the script element\" [1] says:\n\n    \"If src is the empty string, then queue an element task on the DOM\n    manipulation task source given el to fire an event named error at el,\n    and return.\"\n\n    \"If url is failure, then queue an element task on the DOM manipulation\n    task source given el to fire an event named error at el, and return.\"\n\nThese steps run before the switch on el\u0027s type, so they apply to classic\nand module scripts alike.\n\nrequestClassicScript() already queues the task, but requestModuleScript()\ncalled dispatchErrorEvent() directly, so for module scripts the error event\nfired synchronously inside appendChild(). Use the same\nqueueTaskKeepingObjectAlive() pattern as the classic path.\n\n[1] https://html.spec.whatwg.org/multipage/scripting.html#prepare-the-script-element\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326650\nWebKit-Canonical-Link: https://commits.webkit.org/323198@main"
    },
    {
      "commit": "0c8e6e9999057f167da1947a1bea58b08348c4b3",
      "tree": "bf3394379258b091d8e229a1f9844fe4bff840fd",
      "parents": [
        "384004d0601b26a8e09ca3fb252d142f8c438f82"
      ],
      "author": {
        "name": "Ahmad Saleem",
        "email": "52317531+Ahmad-S792@users.noreply.github.com",
        "time": "Fri Oct 09 16:41:44 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 16:41:44 2026"
      },
      "message": "Setting src to the empty string on a connected script element does not fire an error event (#63456)\n\nThis patch aligns WebKit with Gecko / Firefox.\n\nThe script element\u0027s attribute change steps [1] say:\n\n    \"If localName is src, value is not null, and element is connected, then\n    run the script HTML element post-connection steps, given element.\"\n\nScriptElement::handleSourceAttribute() returned early when the value was\nempty rather than null, so setting src to \"\" on a connected script element\nthat had not yet started never prepared it, and the error event required by\n\"If src is the empty string, then queue an element task on the DOM\nmanipulation task source given el to fire an event named error at el, and\nreturn.\" was never fired.\n\nCheck isNull() instead. SVGScriptElement passes href(), which can be the\nempty string when the attribute is removed, so keep its existing behavior by\nskipping the call for an empty href.\n\n[1] https://html.spec.whatwg.org/multipage/scripting.html#script-processing-model\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326652\nWebKit-Canonical-Link: https://commits.webkit.org/323200@main"
    },
    {
      "commit": "384004d0601b26a8e09ca3fb252d142f8c438f82",
      "tree": "1677cbebc3b8e81e279003889233025eae989c4f",
      "parents": [
        "bf7d032062962e28907a9421e67613e6fbc6eab5"
      ],
      "author": {
        "name": "Ahmad Saleem",
        "email": "52317531+Ahmad-S792@users.noreply.github.com",
        "time": "Fri Oct 09 16:41:40 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 16:41:40 2026"
      },
      "message": "MediaList writes are silently dropped after its owner rule or stylesheet is destroyed (#63462)\n\nA MediaList wrapper does not keep its owning CSSMediaRule, CSSImportRule\nor CSSStyleSheet alive. When the owner is destroyed while script still\nholds the MediaList, the owner\u0027s destructor calls detachFromParent(), which\nsnapshots the queries into m_detachedMediaQueries and clears both parent\npointers.\n\nReads were served from that snapshot, but MediaList::setMediaQueries() only\nwrote through the parent pointers. Both are null by then, so the mediaText\nsetter, appendMedium() and deleteMedium() became silent no-ops, and the list\nkept reporting its old value. Whether a write took effect depended on GC\ntiming.\n\nStore writes into m_detachedMediaQueries when the list is detached.\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326790\nWebKit-Canonical-Link: https://commits.webkit.org/323203@main"
    },
    {
      "commit": "bf7d032062962e28907a9421e67613e6fbc6eab5",
      "tree": "7c860b3f3c37bab10692d07e55d84b980efc18f1",
      "parents": [
        "83559739b4d540fed1178267b23bf0f99ce702bc"
      ],
      "author": {
        "name": "Andrew Martinez",
        "email": "amartinez55@apple.com",
        "time": "Thu Oct 08 20:33:43 2026"
      },
      "committer": {
        "name": "Tim Nguyen",
        "email": "nt1m@users.noreply.github.com",
        "time": "Fri Oct 09 16:26:43 2026"
      },
      "message": "Elements using background image from currentColor doesn\u0027t repaint when current color changes\n\nisEquivalentForPainting() only checked background-color for currentColor. currentColors inside background images, like linear-gradient()\ndid not trigger repaints when the objects changed.\n\nStyle::Image::containsCurrentColor() now checks for currentColors in gradients, image, crossfade, filter, and image-set.\nEvery background layer is checked in BackgroundData::backgroundContainsCurrentColor().\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d324766\n"
    },
    {
      "commit": "83559739b4d540fed1178267b23bf0f99ce702bc",
      "tree": "750513860f10710c2447e6e9c3a744044fbc8671",
      "parents": [
        "fc4dce436b08d0bfcec2da90a433b26dc5323870"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Fri Oct 09 08:19:33 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 15:48:59 2026"
      },
      "message": "Fix and re-enable highlight-painting-shadows-vertical.html\n\n`external/wpt/css/css-pseudo/highlight-painting-shadows-vertical.html`\nfailed consistently due to not waiting for Ahem to load. This patch\nfixes this issue by waiting for Ahem to load, removes the failing\nTestExpectations entry, and double-checks that the test is no longer\nflaky.\n\nBug: 568337130, 431033198\nChange-Id: Ic61a9178bb533ccc8117695b628c7c97c5526ab5\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8541574\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nReviewed-by: Rune Lillesveen \u003cfuthark@chromium.org\u003e\nCommit-Queue: Rune Lillesveen \u003cfuthark@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715330}\n"
    },
    {
      "commit": "fc4dce436b08d0bfcec2da90a433b26dc5323870",
      "tree": "915df84fbbb126dc38cf018566bd179e5e2bc9ac",
      "parents": [
        "37db47b966754e6ad7cf20d6d43fa0375db4080d"
      ],
      "author": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Fri Oct 09 05:47:18 2026"
      },
      "committer": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Fri Oct 09 14:15:11 2026"
      },
      "message": "Do not deserialize FileSystemHandle in non-secure contexts\n\nFileSystemHandle is [SecureContext], but posting one to a non-secure\ncontext of the same origin, such as an https frame inside an http page,\ndelivered it there. Use the generated exposure check, through\nisInterfaceExposedInGlobalObject() from 322979@main, so that those\nmessages fail to deserialize and result in a messageerror event.\n\nFileSystemHandle can also be stored in IndexedDB, but a non-secure\ncontext never shares a storage partition with a secure context of the\nsame origin, so there is no IndexedDB equivalent to test.\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326946\n"
    },
    {
      "commit": "37db47b966754e6ad7cf20d6d43fa0375db4080d",
      "tree": "0cb7b193811d7fecb91eeffff790d626db8de59d",
      "parents": [
        "2acf56c32a7b70e88dcec7cc30cfe56bd681196b"
      ],
      "author": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Fri Oct 09 13:53:53 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 13:53:53 2026"
      },
      "message": "Add MutationObserver transient registered observer and callback order tests\n\nA MutationObserver observing a subtree keeps observing a node removed from that subtree, until mutation observers are notified. Test that this happens, also after takeRecords(), for children removed by replaceChildren(), and for nodes moved out of the subtree by moveBefore(), and that it stops:\n\n* when mutation observers are notified, even if no record was queued for the observer or its callback was not invoked;\n* when disconnect() is invoked, without affecting other observers;\n* when observe() replaces the options of the registered observer it originates from, without affecting other registered observers.\n\nEach of these is also tested for nodes removed from an already removed subtree.\n\nAlso test that observe() on a node in a removed subtree registers an observer that remains after mutation observers are notified, that removing a node from an observed subtree queues the mutation observer microtask while other mutations only do so once a record is queued for an observer, and that mutation observers are notified in the order they were created.\n\nFor https://github.com/whatwg/dom/pull/1507"
    },
    {
      "commit": "2acf56c32a7b70e88dcec7cc30cfe56bd681196b",
      "tree": "c65e8cc3d11d2c63b3cafd87b40ff1b3bc660aef",
      "parents": [
        "9914cd827be802c83201eddedfe51beb3bb4d7c0"
      ],
      "author": {
        "name": "Jingyun Liu",
        "email": "jingyun@google.com",
        "time": "Fri Oct 09 03:01:03 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 13:05:27 2026"
      },
      "message": "LanguageModel.prompt() returns a sequence\u003cLanguageModelMessageContent\u003e\nif expecting tool call output\n\n- https://github.com/webmachinelearning/prompt-api/pull/162#discussion_r4154198219\n- previously it returns dynamic types (DOMString if no tool call,\nsequence if has tool call)\n- Now if expectedOutput expects tool call, prompt() will return sequence\n regardless of current model output\n- Update WPT and unit tests to cover the new resolution behavior.\n\nChange-Id: I2d091e22a7d6dd235256b6976d817c760b59fca3\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8504744\nCommit-Queue: Jingyun Liu \u003cjingyun@google.com\u003e\nReviewed-by: Mike Wasserman \u003cmsw@chromium.org\u003e\nReviewed-by: Tom Sepez \u003ctsepez@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715202}\n"
    },
    {
      "commit": "9914cd827be802c83201eddedfe51beb3bb4d7c0",
      "tree": "889608ad370554295bbe008908d8d240ad8d1e01",
      "parents": [
        "b59184b6ef85a5cb29a96a64351dc9228d85bc9e"
      ],
      "author": {
        "name": "Fernando Fiori",
        "email": "ffiori@microsoft.com",
        "time": "Fri Oct 09 01:59:55 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 12:32:41 2026"
      },
      "message": "[focus-without-user-activation] Fix label forwarding\n\nPreserve the calling frame when a label forwards focus to its associated\ncontrol, both for label.focus() and scripted click activation. Losing\nthe caller caused these paths to check the target document\u0027s permissions\npolicy instead.\n\nForward FocusParams::initiator_frame from HTMLLabelElement::Focus(). For\nuntrusted click events, use the incumbent window\u0027s frame as the\ninitiator, matching Element::focusForBindings(). Trusted clicks (user\ninput, accessibility, UA-simulated) still use the label\u0027s frame.\n\nThe new WPT is tentative while initiator attribution is specified:\nhttps://github.com/whatwg/html/issues/12032\n\nBug: 523708065\nChange-Id: I2e4ac1ba4a6b836594512105e21ed03e5668a528\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8464353\nReviewed-by: Jacques Newman \u003cjanewman@microsoft.com\u003e\nReviewed-by: Dan Clark \u003cdaniec@microsoft.com\u003e\nCommit-Queue: Fernando Fiori \u003cffiori@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1715143}\n"
    },
    {
      "commit": "b59184b6ef85a5cb29a96a64351dc9228d85bc9e",
      "tree": "a7373dd42259f5cbff2bf8b5a5fb3834e5e8284e",
      "parents": [
        "72048bce931b8c75165ab661b0f16ef7c7b7460e"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Fri Oct 09 01:59:37 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 12:32:33 2026"
      },
      "message": "[html-in-canvas] Remove legacy getElementTransform API\n\nThis patch removes the legacy 2-argument `getElementTransform(element,\ndraw_transform)` method from `HTMLCanvasElement` and `OffscreenCanvas`,\nretaining the 1-argument `HTMLCanvasElement.getElementTransform(element)`\nmethod that reads the stored element canvas transform.\n\nTransform calculation test coverage from the removed legacy tests (such\nas canvas/CSS pixel scaling, zoom, CTM transforms, `transform-origin`,\nand source rect offsets) has been migrated to `canvas-transform-update`\nand `canvas-transform-update-worker` via `drawElementImage()`.\n\nFixed: 571496925\nChange-Id: Ie9484247714ef6a621132c27da60bb043f088208\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8542152\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nReviewed-by: Stefan Zager \u003cszager@chromium.org\u003e\nCommit-Queue: Stefan Zager \u003cszager@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715079}\n"
    },
    {
      "commit": "72048bce931b8c75165ab661b0f16ef7c7b7460e",
      "tree": "751b949dd6908d29c04e8634f91a1929d6fb46ea",
      "parents": [
        "d191fa8bbab9d678b76e31f243fabcf5530e40f2"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Fri Oct 09 12:30:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 12:30:54 2026"
      },
      "message": "Sync interfaces/ with @webref/idl 3.85.1 (#63368)\n\nCo-authored-by: wpt-pr-bot \u003cwpt-pr-bot@users.noreply.github.com\u003e"
    },
    {
      "commit": "d191fa8bbab9d678b76e31f243fabcf5530e40f2",
      "tree": "f2d5499c8d761d4d206661cd9a4b2005f2859a58",
      "parents": [
        "e4a9e438d3542b0ca9e6e56f9fa838ed30ba72d7"
      ],
      "author": {
        "name": "Maksim Sadym",
        "email": "69349599+sadym-chromium@users.noreply.github.com",
        "time": "Fri Oct 09 12:22:35 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 12:22:35 2026"
      },
      "message": "[testdriver] Add test_driver.bidi.emulation.set_viewport_meta_override (#62938)\n\nSpec: https://w3c.github.io/webdriver-bidi/#command-emulation-setViewportMetaOverride"
    },
    {
      "commit": "e4a9e438d3542b0ca9e6e56f9fa838ed30ba72d7",
      "tree": "1d6708bfb2b2f391278ec18d19dffa9eaf0b5e40",
      "parents": [
        "1317e80115b1df439f420d8ddc16aa587d72729b"
      ],
      "author": {
        "name": "rayguo17",
        "email": "rayguo17@gmail.com",
        "time": "Thu Oct 08 11:18:11 2026"
      },
      "committer": {
        "name": "Servo WPT Sync",
        "email": "32481905+servo-wpt-sync@users.noreply.github.com",
        "time": "Fri Oct 09 11:38:30 2026"
      },
      "message": "address comment\n\nSigned-off-by: rayguo17 \u003crayguo17@gmail.com\u003e\n"
    },
    {
      "commit": "1317e80115b1df439f420d8ddc16aa587d72729b",
      "tree": "52c7d5bc9343e9a2a74c6d8b358347d76d0255c4",
      "parents": [
        "6d1e51c31bfd62f89ec36a433eb1d652a75f9389"
      ],
      "author": {
        "name": "rayguo17",
        "email": "tin.tun.aung1@huawei.com",
        "time": "Thu Oct 08 11:18:10 2026"
      },
      "committer": {
        "name": "Servo WPT Sync",
        "email": "32481905+servo-wpt-sync@users.noreply.github.com",
        "time": "Fri Oct 09 11:38:30 2026"
      },
      "message": "change EOL to LF\n\nSigned-off-by: rayguo17 \u003ctin.tun.aung1@huawei.com\u003e\n"
    },
    {
      "commit": "6d1e51c31bfd62f89ec36a433eb1d652a75f9389",
      "tree": "f43e64d0d1501980fcfae75fec9f8e4789bf3347",
      "parents": [
        "e5eca838839adb2cc0c04a7959d6be602325fa00"
      ],
      "author": {
        "name": "rayguo17",
        "email": "tin.tun.aung1@huawei.com",
        "time": "Thu Oct 08 11:18:10 2026"
      },
      "committer": {
        "name": "Servo WPT Sync",
        "email": "32481905+servo-wpt-sync@users.noreply.github.com",
        "time": "Fri Oct 09 11:38:30 2026"
      },
      "message": "added wpt test for this scenario\n\nSigned-off-by: rayguo17 \u003ctin.tun.aung1@huawei.com\u003e\n"
    },
    {
      "commit": "e5eca838839adb2cc0c04a7959d6be602325fa00",
      "tree": "cfaee6ecb9ffc14aa7ea0462a70dedba5940c671",
      "parents": [
        "3e22fa4e75778f91795fda7e14c82f067fb2a156"
      ],
      "author": {
        "name": "Josh Bowman-Matthews",
        "email": "josh@joshmatthews.net",
        "time": "Thu Oct 08 11:18:10 2026"
      },
      "committer": {
        "name": "Servo WPT Sync",
        "email": "32481905+servo-wpt-sync@users.noreply.github.com",
        "time": "Fri Oct 09 11:38:30 2026"
      },
      "message": "wpt: Run CSS fetching tests (#48716)\n\nThese changes enable a new subdirectory and fix some problems that were\ncausing the tests to timeout.\n\nTesting: New passing subtest\n\n---------\n\nSigned-off-by: Josh Matthews \u003cjosh@joshmatthews.net\u003e\n"
    },
    {
      "commit": "3e22fa4e75778f91795fda7e14c82f067fb2a156",
      "tree": "331467641bc85822b5f21857e3ca38ba94715bff",
      "parents": [
        "83381e6080f07d775a4fc9d33adc4bffbd13186c"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Fri Oct 09 01:27:54 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 11:25:43 2026"
      },
      "message": "[html-in-canvas] Remove blink-specific terms in WPTs\n\nThis patch removes some blink-specific implementation terms in the\ndraw-element-image tests.\n\nChange-Id: I9d303a0984a4c8a51230846b67a3f34af36da1db\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8545050\nCommit-Queue: Philip Rogers \u003cpdr@chromium.org\u003e\nCommit-Queue: Stefan Zager \u003cszager@chromium.org\u003e\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nReviewed-by: Stefan Zager \u003cszager@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715139}\n"
    },
    {
      "commit": "83381e6080f07d775a4fc9d33adc4bffbd13186c",
      "tree": "ce40ae399670c0b4368b3f056098fd2c4d7c1d18",
      "parents": [
        "05d3e3785d1c6983cf65af0d6b36f37cf8843f5b"
      ],
      "author": {
        "name": "Dan Murphy",
        "email": "dmurph@chromium.org",
        "time": "Fri Oct 09 01:27:43 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 11:25:36 2026"
      },
      "message": "[Notifications] SW popup capability delegation\n\nWhen handling a notification click, a Service Worker may need an\nexisting client window to open a popup (e.g. an email preview or chat\ncompose). Currently, window.open() in the client is blocked by the popup\nblocker because the client window lacks transient user activation.\n\nThis CL allows the Service Worker to delegate popup capability to a\nsame-origin WindowClient via client.postMessage(msg, {delegate:\n\u0027popup\u0027}). Upon receipt, the client window receives a 1-second transient\npopup token enabling window.open(). This is decoupled from window\ninteraction and gated behind the CapabilityDelegationPopup feature flag.\n\nSee https://chromestatus.com/feature/5091965583622144\n\nBug: 542314185, b:529458813\nTest: http/tests/serviceworker/clients-capability-delegation.html\nTest: external/wpt/html/capability-delegation/\nTest: blink_unittests --gtest_filter\u003dWebFrameTest.CapabilityDelegation*\nChange-Id: I43dcdbf25b6585f9fcdb8a49f9810037136aec5e\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8069089\nReviewed-by: Marijn Kruisselbrink \u003cmek@chromium.org\u003e\nCommit-Queue: Daniel Murphy \u003cdmurph@chromium.org\u003e\nReviewed-by: Nasko Oskov \u003cnasko@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715121}\n"
    },
    {
      "commit": "05d3e3785d1c6983cf65af0d6b36f37cf8843f5b",
      "tree": "63fb091f208d57463bd7ac4687886aec5c47151b",
      "parents": [
        "221aceb1f809efebbff2dec2d5682921d520e448"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Fri Oct 09 01:27:32 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 11:25:29 2026"
      },
      "message": "Deflake cdata-001.xhtml and cdata-002.xhtml by waiting for Ahem\n\n`wpt/html/rendering/cdata-001.xhtml` and\n`wpt/html/rendering/cdata-002.xhtml` are flaky due to not waiting for\nAhem to load. When the tests are run by themselves, the flakiness is\nconsistently reproducible without this patch and goes away with this\npatch, which waits for the font to be ready. This patch has a small\nspecial-case because the fonts may not load until the non-empty xhtml\nwith the Ahem font is present, so a second await is needed.\n\nBug: 568337130\nChange-Id: Ic739279bde8f84527bd8c9225ab63d78c3c1e430\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8542234\nCommit-Queue: Kent Tamura \u003ctkent@chromium.org\u003e\nReviewed-by: Kent Tamura \u003ctkent@chromium.org\u003e\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715116}\n"
    },
    {
      "commit": "221aceb1f809efebbff2dec2d5682921d520e448",
      "tree": "2bc325839183326374a4aa1afd9c8afb5abdcbed",
      "parents": [
        "6fc3c827bc4f9e1f48ff71bfecaab52eac5ed144"
      ],
      "author": {
        "name": "Emilio Cobos Álvarez",
        "email": "emilio@crisal.io",
        "time": "Thu Oct 08 18:37:29 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Fri Oct 09 10:11:00 2026"
      },
      "message": "Don\u0027t ignore a closing curly bracket from within the declaration parser.\n\nThis gets the behavior that matches other browsers and is a one-liner.\n\nIf you\u0027re in a block, `}` is the delimiter anyway (so the iterator can\u0027t\nsee it). Otherwise if you\u0027re not parsing qualified rules you go to the\nskip-until-semicolon path.\n\nThe spec is a bit broken here, see\nhttps://github.com/w3c/csswg-drafts/issues/14565, thus the tentative\ntest for now.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331713\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2065482\ngecko-commit: 1ce28331ff835a3471744c9b68498fdda3524b54\ngecko-commit-git: 23f75c3ebb25e7353464682e40a61ffff4dce792\ngecko-reviewers: firefox-style-system-reviewers, dshin, supply-chain-reviewers\n"
    },
    {
      "commit": "6fc3c827bc4f9e1f48ff71bfecaab52eac5ed144",
      "tree": "091e53d455f977f31a147216ddfb1636868230c3",
      "parents": [
        "9fd55a8464bf08be2f2b9a8415a5e42d362aac9a"
      ],
      "author": {
        "name": "Daniel Holbert",
        "email": "dholbert@cs.stanford.edu",
        "time": "Thu Oct 08 16:41:47 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Fri Oct 09 10:08:33 2026"
      },
      "message": "When applying size-containment from content-visibility, more-robustly check whether we already have size-containment.\n\nNote that StyleContain::SIZE is a *bitfield with multiple bits* (including a\nbit for inline-axis containment and a different bit for block-axis\ncontainment).\n\nThe old code that existed before this patch was (mistakenly) using\n`mEffectiveContainment \u0026 StyleContain::SIZE` as a test for whether we\u0027re\nsize-contained in both axes; and it was using the result of that expression as\nan optimization to skip some code that might apply size-containment in both\naxes (which we can trivially skip if we\u0027re already size-contained in both\naxes).\n\nThis logic wasn\u0027t valid -- since `StyleContain::SIZE` is a multi-bit bitfield,\nthe old code was actually just checking whether we had size-containment\n**in any axis**, which is clearly insufficient as a justification to skip code\nthat would apply size containment in **both** axes.\n\nThis patch fixes this issue by actually robustly checking for size-containment\nin both axes, and only skipping the `HidesContent()` call if we\u0027re\nsize-contained in both axes (in which case we\u0027re going to return\nContainSizeAxes(true, true) in the function\u0027s final return statement).\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331495\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2079026\ngecko-commit: 4ef46045616f25c792623a837e74f7f1bbcba3bd\ngecko-commit-git: 8e18f67fb66f6b0e86811716d2e1e7145ff7caa8\ngecko-reviewers: layout-reviewers, firefox-style-system-reviewers, emilio\n"
    },
    {
      "commit": "9fd55a8464bf08be2f2b9a8415a5e42d362aac9a",
      "tree": "5b4c549cd5a5953f456f1570aeb2fc1e0574fa30",
      "parents": [
        "d7f802deee5455c0ea0ab7553b2f2b3a14cf666e"
      ],
      "author": {
        "name": "Dale Curtis",
        "email": "dalecurtis@chromium.org",
        "time": "Fri Oct 09 00:21:51 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 07:46:10 2026"
      },
      "message": "[WebCodecs] Fix fractional display size scaling on visibleRect override\n\nCast default_display_size.width() and default_display_size.height() to\ndouble before dividing by default_visible_rect dimensions in\nParsedVideoFrameInit(). Previously, integer division truncated\nnon-integer display-to-visible ratios to integers, producing incorrect\ndisplay dimensions for fractional scales \u003e 1 and throwing spurious\nTypeErrors when scales \u003c 1 truncated to zero.\n\nFixed: 562847603\nChange-Id: I63cabd61bdc1a38d3599114288e59d0c82431694\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8540370\nReviewed-by: Eugene Zemtsov \u003ceugene@chromium.org\u003e\nCommit-Queue: Dale Curtis \u003cdalecurtis@chromium.org\u003e\nCommit-Queue: Eugene Zemtsov \u003ceugene@chromium.org\u003e\nAuto-Submit: Dale Curtis \u003cdalecurtis@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715044}\n"
    },
    {
      "commit": "d7f802deee5455c0ea0ab7553b2f2b3a14cf666e",
      "tree": "a20f8ee8d7cb8a2c5b1f2bacb1d0a214e046dd4f",
      "parents": [
        "1214c0bce69b13d746f0324ae59a0ceee7382469"
      ],
      "author": {
        "name": "Mason Freed",
        "email": "masonf@chromium.org",
        "time": "Fri Oct 09 00:21:40 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 07:46:01 2026"
      },
      "message": "Don\u0027t hold a reference to the id attribute across UpdateId()\n\nElement::InsertedInto() took a reference into the element\u0027s attribute\nstorage via GetIdAttribute() and passed it to UpdateId(). UpdateId()\nnotifies id target observers, and those can update style and layout.\nFor example, a focused \u003cinput list\u003e whose datalist became usable\nrebuilds its shadow tree and calls RevealSelection(). If that update\nbuilds a \u003cuse\u003e instance tree that clones the element, cloning\nserializes the element\u0027s dirty style attribute and appends it to the\nattribute storage. When that reallocates the storage, the reference\ndangles, and the remaining reads of the id in UpdateId() access freed\nmemory.\n\nThis CL copies the id into a local AtomicString before calling\nUpdateId(). RemovedFrom() passes the id to UpdateId() the same way, so\nit gets the same change. Recent fixes for similar bugs in\nElementRuleCollector and HTMLAnchorElementBase::NavigateToHyperlink()\nused the same approach.\n\nFixed: 567638392\nChange-Id: I1ebac072098091e5dc9d8898f2bced3cf0c3bbcc\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8517119\nAuto-Submit: Mason Freed \u003cmasonf@chromium.org\u003e\nReviewed-by: David Baron \u003cdbaron@chromium.org\u003e\nCommit-Queue: Mason Freed \u003cmasonf@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1715019}\n"
    },
    {
      "commit": "1214c0bce69b13d746f0324ae59a0ceee7382469",
      "tree": "2c449a02fea428505ce0f0892d0beef5dabd0156",
      "parents": [
        "10ccd8604683524790a9493d68965c2878107afe"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Thu Oct 08 22:55:49 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 06:42:50 2026"
      },
      "message": "[SAH] Remove stale expectation and harden storage-access-headers WPT\n\nstorage-access-headers.tentative.https.sub.window.html has been marked\n[ Failure Timeout ] since the storage-access-api WPTs started running\nagainst Chrome (via ChromeDriver) instead of content_shell, because the\nStorage Access API is implemented in the //chrome layer. The causes of\nthose failures have since been fixed (ChromeDriver\u0027s SetPermission frame\norigin, the test assuming cross-site cookies are blocked by default, and\nSetFirstPartyCookie\u0027s `{ once: true }` listener being detached by stray\nmessages), and the test now passes reliably, so remove the expectation.\n\nAlso clean up the test itself:\n\n* Run areCrossSiteCookiesAllowedByDefault() inside promise_setup()\n  instead of an unawaited async IIFE. Previously the first three\n  promise_tests started running while the probe frame was still being\n  loaded and messaged, so the probe ran concurrently with subtests that\n  create cross-site frames and set storage-access permissions for the\n  same origin.\n\n* Remove the responder iframes created by the probe and by five\n  subtests once they are no longer needed. These frames load\n  testharness.js and post a `{type: \"complete\"}` message to every\n  ancestor when their 10s harness timeout fires, and keeping them\n  around leaves cross-site frames alive for the remainder of the test.\n\nTAG\u003dagy\nCONV\u003d0d875fba-fe1a-401b-9481-9a9d918e0eca\n\nBug: 366530634\nChange-Id: I058f027f2890290c5fbd4539310b966010f49523\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8520603\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCommit-Queue: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nReviewed-by: Chris Fredrickson \u003ccfredric@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714977}\n"
    },
    {
      "commit": "10ccd8604683524790a9493d68965c2878107afe",
      "tree": "ddaa4f5dcf6d53175ee304e4e56d83073513b2c6",
      "parents": [
        "385f52fe54bdea1383e8621675ce6727be9d076b"
      ],
      "author": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Thu Oct 08 10:20:15 2026"
      },
      "committer": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Fri Oct 09 06:05:05 2026"
      },
      "message": "Do not deserialize RTCCertificate in workers\n\nRTCCertificate is [Exposed\u003dWindow], but posting one to a dedicated,\nshared, or service worker delivered it there. Use the generated exposure\ncheck, through isInterfaceExposedInGlobalObject() from 322979@main, so\nthat those messages fail to deserialize and result in a messageerror\nevent.\n\nRTCCertificate can also be stored in IndexedDB, and reading one back in a\nworker used to deliver it there too. Now that it fails to deserialize,\nIDBRequest\u0027s result, IDBCursorWithValue\u0027s value, and IDBRecord\u0027s value\nwould be null, silently losing the record. Align with Firefox instead:\nthe request succeeds and reading the value throws. Throw a DataCloneError\nrather than Firefox\u0027s InvalidStateError, as proposed in\nhttps://github.com/w3c/IndexedDB/issues/391\n\n(Chromium deserializes as null, which seems less useful.)\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326793\n"
    },
    {
      "commit": "385f52fe54bdea1383e8621675ce6727be9d076b",
      "tree": "6dd922ad1c0ea69729c89bdb9458822a14ffc575",
      "parents": [
        "5717e380cdca8ed08a1f8e3bdd279beace9166da"
      ],
      "author": {
        "name": "Mike Taylor",
        "email": "miketaylr@chromium.org",
        "time": "Thu Oct 08 21:49:11 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 05:10:56 2026"
      },
      "message": "[wpt] Fix webauthn add_credential/invalid.py null signCount expectation\n\nThe test asserted that `signCount: null` must be rejected with\n\"invalid argument\". However, w3c/webauthn#2382 made signCount nullable\nto represent a credential without a signature counter, and ChromeDriver\nimplements this (see crrev.com/c/fc0cd539d551b \"[chromedriver] Support\nnull signature counters\"). The sibling set_credential_properties/set.py\ntest already treats `None` as a valid signCount, so invalid.py was\ninternally inconsistent with the rest of the suite. This made\ntest_sign_count_invalid_type[None] fail deterministically on all\nplatforms.\n\nRemove `None` from the invalid-type cases and add a positive test in\nadd.py asserting that a credential with a null signCount is accepted\nand read back with `signCount \u003d\u003d null`.\n\nRemoves the [ Failure ] expectation. Both add.py and invalid.py pass\nlocally with run_wpt_tests.py (36 subtests).\n\nBug: 533056772\nChange-Id: Ia8cecaf642a11dcfeab2ddf7830de6d4331be7a1\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8540564\nReviewed-by: Martin Kreichgauer \u003cmartinkr@google.com\u003e\nAuto-Submit: Mike Taylor \u003cmiketaylr@chromium.org\u003e\nCommit-Queue: Martin Kreichgauer \u003cmartinkr@google.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714914}\n"
    },
    {
      "commit": "5717e380cdca8ed08a1f8e3bdd279beace9166da",
      "tree": "6f728249e8e084b487ac0f1c618ac423e75718d9",
      "parents": [
        "af6c5926d57293c3af16483726ef876c7a348b30"
      ],
      "author": {
        "name": "Ahmad Saleem",
        "email": "52317531+Ahmad-S792@users.noreply.github.com",
        "time": "Fri Oct 09 02:08:15 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Oct 09 02:08:15 2026"
      },
      "message": "[SVG2] Implement the side attribute for SVG \u003ctextPath\u003e element (#63430)\n\nSVG2 adds the \u0027side\u0027 attribute to \u003ctextPath\u003e with values \u0027left\u0027 (default)\nand \u0027right\u0027 [1]. Per the spec, side\u003d\"right\" lays the text out along the\nreversed path, which renders it on the opposite side of the curve. WebKit\ndid not expose the attribute on the DOM or honor it during layout.\n\nExpose \u0027side\u0027 as an SVGAnimatedEnumeration (SVGTextPathSideType, with the\nTEXTPATH_SIDETYPE_LEFT/RIGHT constants), mirroring the existing \u0027method\u0027\nand \u0027spacing\u0027 enumerations, with \u0027left\u0027 as the lacuna value and invalid\nvalues reset to the initial value \u0027left\u0027 via the shared parseBaseVal\nhelper (matching method/spacing). The SVG WG resolved to add the side\nconstants to the SVGTextPathElement IDL [3].\n\nFor rendering, walking the reversed path at arc length t is equivalent to\nsampling the forward path at (pathLength - t) and rotating each glyph by\n180 degrees, so no path-reversal primitive is needed (WebCore::Path has\nnone). SVGTextLayoutEngine carries a reversed flag set from the textPath\nrenderer and applies the mirrored sampling and angle flip in the path\nlayout loop; the existing baseline/orientation math composes correctly\nbecause it operates on the reversed tangent angle.\n\n[1] https://w3c.github.io/svgwg/svg2-draft/single-page.html#text-TextPathAttributes\n[2] https://github.com/w3c/svgwg/issues/1086\n[3] https://www.w3.org/2026/04/23-svg-minutes.html\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d311609\nWebKit-Canonical-Link: https://commits.webkit.org/323115@main"
    },
    {
      "commit": "af6c5926d57293c3af16483726ef876c7a348b30",
      "tree": "dcc30936cc6650d2c2e8d562b60dc713c8a51f5c",
      "parents": [
        "3a9899331fe9eedee8669bca985ee58c1a7f6cc4"
      ],
      "author": {
        "name": "Vladimir Levin",
        "email": "vmpstr@chromium.org",
        "time": "Thu Oct 08 19:20:24 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:59:17 2026"
      },
      "message": "VT: Keep remembered size if style has contain-intrinsic-size: auto\n\nThis patch ensures that we keep the VT remembered size if it needs one\noutside of the capture phase (ie the author style has\ncontain-intrinsic-size).\n\nR\u003dfreedebreuil@google.com\n\nChange-Id: I3bf6f935d69629a9bbebe39d6b5b695cac29ddd1\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8519137\nReviewed-by: Free Debreuil \u003cfreedebreuil@google.com\u003e\nCommit-Queue: Vladimir Levin \u003cvmpstr@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714775}\n"
    },
    {
      "commit": "3a9899331fe9eedee8669bca985ee58c1a7f6cc4",
      "tree": "7d4d5fc01dbbcba51d1352003dea8b9247f99334",
      "parents": [
        "e20cc479197289f01436bd9e319bf6d5cc7169c7"
      ],
      "author": {
        "name": "Joey Arhar",
        "email": "jarhar@chromium.org",
        "time": "Thu Oct 08 18:46:19 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:59:12 2026"
      },
      "message": "Fix flake in select-4-option-optgroup-display-none.html\n\nSet will-change: transform on :root in\nselect-4-option-optgroup-display-none.html and its reference file to\nprevent subpixel rendering differences on the rounded corners of the\n\u003cselect size\u003d4\u003e elements, and remove the failure expectation.\n\nThe flake was reproduced using UTR against \u0027Linux Tests (dbg)(1)\u0027\n(headless_shell_wpt_tests with --repeat-each\u003d10), where 1 out of 10 runs\nfailed with a 1-channel-value difference on the rounded corner pixels.\nAfter adding will-change: transform, all 20 runs with --repeat-each\u003d20\non \u0027Linux Tests (dbg)(1)\u0027 passed without any failures.\n\nFixed: 567713221\nChange-Id: I51b8519f4343aa997cc933a39aa748faf23d436b\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8503877\nReviewed-by: Joey Arhar \u003cjarhar@chromium.org\u003e\nCommit-Queue: Joey Arhar \u003cjarhar@chromium.org\u003e\nReviewed-by: Mason Freed \u003cmasonf@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714719}\n"
    },
    {
      "commit": "e20cc479197289f01436bd9e319bf6d5cc7169c7",
      "tree": "5bf7d5d67da16690b80ec6d0df43a0b81da3eb75",
      "parents": [
        "eb1f17915b157f7c2449f4daccfaace3a5f49959"
      ],
      "author": {
        "name": "Steve Becker",
        "email": "stevebe@microsoft.com",
        "time": "Thu Oct 08 18:14:47 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:27:04 2026"
      },
      "message": "[SVG] Make SVGPathElement::getPathSegmentAtLength() use the base value\n\n... instead of the animated value. This is consistent with other\nbrowsers. It\u0027s also consistent with `SVGPathElement::getPathData()`. The\nsegment returned by `getPathSegmentAtLength()` should exist in the\nsequence returned by `getPathData()`.\n\nBug: 40441025\nChange-Id: Ie531507395762cb89eef5eebeeb3a10d00440b7b\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8534547\nReviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\nCommit-Queue: Steve Becker \u003cstevebe@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714693}\n"
    },
    {
      "commit": "eb1f17915b157f7c2449f4daccfaace3a5f49959",
      "tree": "ed4a9308d7455571414f01265fa92115f2fe6114",
      "parents": [
        "66f9f7f3d4a6ceca604f9a0519860a16f7610834"
      ],
      "author": {
        "name": "Andrew Verge",
        "email": "averge@chromium.org",
        "time": "Thu Oct 08 18:14:28 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:26:57 2026"
      },
      "message": "[Connection-Allowlist] Enforce WebRTC blocking in binders via no-op impls\n\nPreviously, WebRTC blocking by the Connection Allowlist was decided in\nPopulateBinderMapWithContext(): when the enforced allowlist blocked\nWebRTC, the MdnsResponder and P2PSocketManager binders were never\nregistered. This had two problems:\n\n1. The wrong Connection Allowlist was checked. The binder map is built\n   once, when the BrowserInterfaceBroker is created: in\n   CreateRenderFrame() or FrameTree::AddFrame() for a new\n   frame, and again in DidCommitNavigation(). The commit path\n   rebuilds the broker before DidCommitNewDocument() installs the\n   new document\u0027s PolicyContainerHost, so the check saw the previous\n   document\u0027s policies (typically those of the initial empty document).\n\n2. Unregistered interfaces crashed the renderer. The renderer still\n   requests MdnsResponder and P2PSocketManager when it creates the peer\n   connection factory, which occurs in the RTCPeerConnection constructor.\n   With no binder registered, BrowserInterfaceBrokerImpl calls\n   ReportNoBinderForInterface(), which reports a bad message and kills the\n   renderer. This crash was mainly reproducible for nested about:blank and\n   about:srcdoc frames. Because they are created after the parent navigation\n   commit, they inherit the correct allowlist from their parent, which means\n   they never actually bind the interfaces when WebRTC is blocked.\n\nThis CL fixes both:\n\n- The Connection Allowlist check now runs inside the binder functions\n  (BindSocketManager() and RenderFrameHostImpl::CreateMdnsResponder()).\n  They run only when the renderer actually requests the interface,\n  which happens from script in an already-committed document, so the\n  check reads that document\u0027s policy container. Both binders are now\n  always registered, so the renderer can no longer be killed for\n  requesting them.\n\nHowever, this fix introduces another potential issue. Which is\nthat any IPC sent to these now-correctly-unbound interfaces will\nnever fire callbacks, leaving potential for hangs in renderer-side\ncode.\n\nNow, when WebRTC is blocked, the binders bind no-op implementations\ninstead of dropping the receiver:\n\n- NoOpP2PSocketManager reports an empty network list, returns no\naddresses from GetHostAddress(), and closes the pipes passed to\nCreateSocket(). It stays connected, so the renderer\u0027s\nP2PSocketDispatcher does not enter its reconnect loop.\n\n- NoOpMdnsResponder runs every reply callback with failure values\nand never registers or announces a name.\n\nSo calls from production code fail gracefully instead of hanging or\ncrashing, and no sockets are created and no mDNS names are registered,\nwhatever the renderer does.\n\nThis also removes the fenced-frame P2PSocketManager ban from the binder\nmap, as part of the ongoing removal of fenced frames.\n\nTests:\n- New content_unittests: NoOpMdnsResponderTest.*,\nNoOpP2PSocketManagerTest.*\n- New WPTs covering nested child about:blank / about:srcdoc frames under\na parent\u0027s Connection Allowlist, verifying they do not crash and\nproperly respect the WebRTC parameter of the inherited allowlist.\n- Existing virtual/connection-allowlist WebRTC WPTs continue to pass.\n\nTAG\u003dagy\nCONV\u003de2464277-4d92-41dc-a35f-278d6b893a90\n\nBug: 565837691\nFixed: 565837691\nChange-Id: Id0aeb1a30b7b47163b74898ab11e8ddac37ad9ff\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8485457\nReviewed-by: Giovanni Ortuno Urquidi \u003cortuno@chromium.org\u003e\nCommit-Queue: Andrew Verge \u003caverge@chromium.org\u003e\nReviewed-by: Danil Chapovalov \u003cdanilchap@chromium.org\u003e\nReviewed-by: Guido Urdaneta \u003cguidou@chromium.org\u003e\nReviewed-by: Alex Moshchuk \u003calexmos@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714691}\n"
    },
    {
      "commit": "66f9f7f3d4a6ceca604f9a0519860a16f7610834",
      "tree": "0bfbe08896fa6a372189912ace0a786a3c8febda",
      "parents": [
        "3e9d67f958967c0fb2233ce74c388af3b1e50be7"
      ],
      "author": {
        "name": "Fredrik Söderquist",
        "email": "fs@opera.com",
        "time": "Thu Oct 08 18:14:15 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:26:49 2026"
      },
      "message": "Preserve \u0027none\u0027 keywords across relative color resolution\n\nPer [1]:\n\n\u003e The component keywords return a \u003cnumber\u003e, or \u0027none\u0027.\n\nFactor out a ToChannelValue() helper from UnresolvedRelativeColor\u0027s\nResolve() implementation and make it handle an expression that consists\nof only a component keyword reference. Pass std::optional\u003cfloat\u003e via\nEvaluationInput so that any \u0027none\u0027 keywords are preserved. Use\nColor::ConvertToColorSpaceForInterpolation() so that component keywords\nare carried forward through any conversion. Drop the explicit conversion\nfrom UnresolvedAlphaColor::Resolve() since it will be handled\ndownstream.\n\n[1] https://drafts.csswg.org/css-color-5/#relative-syntax\n\nFixed: 569954059\nChange-Id: Iae2788a09ac775b32790205176100eeafa95d567\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8515517\nReviewed-by: Kevin Babbitt \u003ckbabbitt@microsoft.com\u003e\nCommit-Queue: Fredrik Söderquist \u003cfs@opera.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714679}\n"
    },
    {
      "commit": "3e9d67f958967c0fb2233ce74c388af3b1e50be7",
      "tree": "a583c9a02d3b1171b5f6bd489b3d3784df476562",
      "parents": [
        "1e4070e021b776ad9004e9db8d5f005f02517b77"
      ],
      "author": {
        "name": "Fernando Fiori",
        "email": "ffiori@microsoft.com",
        "time": "Thu Oct 08 18:14:02 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:26:40 2026"
      },
      "message": "Remove void element end tags from HTML embedded and forms WPTs\n\nbase, img, input, embed, source, param and frame have no end tag.\nWriting their end tag anyway is a parse error, and the parser drops the\ntag so the source suggests a structure the document never had.\n\nThis CL removes those invalid end tags from\nthird_party/blink/web_tests/external/wpt/html/semantics/embedded-content\nand third_party/blink/web_tests/external/wpt/html/semantics/forms.\n\nNo behavior change.\n\nBug: 542686202\nChange-Id: I41f4e45c6e093e997533707a5afa8f411a1568a1\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8227044\nReviewed-by: Andres Regalado Rosas \u003candresrega@microsoft.com\u003e\nAuto-Submit: Fernando Fiori \u003cffiori@microsoft.com\u003e\nCommit-Queue: Fernando Fiori \u003cffiori@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714639}\n"
    },
    {
      "commit": "1e4070e021b776ad9004e9db8d5f005f02517b77",
      "tree": "4c977a9d1eed5b6ea8e235ac706bac495206be31",
      "parents": [
        "dcdb8e113ce06c809e3ae44c9731544168fbbd04"
      ],
      "author": {
        "name": "Evan Stade",
        "email": "evanstade@microsoft.com",
        "time": "Thu Oct 08 17:16:08 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:26:33 2026"
      },
      "message": "BackgroundFetch: stop using Blobs during request lookup\n\nWhen retrieving a request body from cache storage, don\u0027t wrap it in a\nBlob. The Blob is immediately redirected into a DataPipeGetter anyway\nwhen used by the browser for the upload/download. Registration of a\nBlobDataItem/BlobDataItemReader with the BlobContext is unnecessary\ncomplexity which uses extra mojo pipes and async steps. If the request\nis retrieved by the renderer with Match, the Blob wrapper is again\nunnecessary most of the time.\n\nThis change doesn\u0027t affect the lifetime of data: as with the\nBlobDataItem before it, the DataPipeGetter will stop working if the\ncache storage entry needs to be deleted.\n\n\"GetRequestBlob\" symbol names are changed to \"GetRequestBody\" in many\nplaces.\n\nAlso add WPT coverage for BgF uploads. (It seems like ReadableStream\nbody *should* be supported, but currently is not, so that\u0027s left out of\nthe test.)\n\nBypass-Check-License: file rename\nBug: 567175133\nChange-Id: Iba326621c2f6930d5d275bb1a95330fb70d69873\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8444651\nReviewed-by: Tommy Nyquist \u003cnyquist@chromium.org\u003e\nCommit-Queue: Evan Stade \u003cevanstade@microsoft.com\u003e\nReviewed-by: Rick Byers \u003crbyers@chromium.org\u003e\nReviewed-by: Rakina Zata Amni \u003crakina@chromium.org\u003e\nReviewed-by: Fergal Daly \u003cfergal@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714621}\n"
    },
    {
      "commit": "dcdb8e113ce06c809e3ae44c9731544168fbbd04",
      "tree": "7f4434e6b3bf4a3b15b58dde9e67f3fe51b38e67",
      "parents": [
        "acd62d7e8b8e7ad080797555a8ce4dbfa9c75cd8"
      ],
      "author": {
        "name": "Philip Rogers",
        "email": "pdr@chromium.org",
        "time": "Thu Oct 08 17:15:56 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 01:26:26 2026"
      },
      "message": "[html-in-canvas] Switch to canvas getter for element width/height\n\nElementImage violated [1] due to being a mix of static and live. This\npatch makes ElementImage static and moves the width/height data to a\ngetter on canvas, as the data depends on canvas width/height\nattributes.\n\n[1] https://w3ctag.github.io/design-principles/#live-vs-static\n\nChange-Id: I75edadd24f985b64b974392a5145fb00e5454fdd\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8531547\nReviewed-by: Stefan Zager \u003cszager@chromium.org\u003e\nAuto-Submit: Philip Rogers \u003cpdr@chromium.org\u003e\nCommit-Queue: Stefan Zager \u003cszager@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714586}\n"
    },
    {
      "commit": "acd62d7e8b8e7ad080797555a8ce4dbfa9c75cd8",
      "tree": "2ef55641c63b79c56602fe50c8c073bce8b4f4ed",
      "parents": [
        "71b4d5f0eb7628a5d5f7cd2ee868ce1b1b5dc010"
      ],
      "author": {
        "name": "luci-bisection@appspot.gserviceaccount.com",
        "email": "luci-bisection@appspot.gserviceaccount.com",
        "time": "Thu Oct 08 18:46:30 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Fri Oct 09 00:54:42 2026"
      },
      "message": "Revert \"Keep wavy text decorations continuous across fragments\"\n\nThis reverts commit 198d0b60e4b380d9af19291d6f36813a808c675b.\n\nReason for revert:\nLUCI Bisection has identified this change as the cause of a test failure. See the analysis: https://ci.chromium.org/ui/p/chromium/bisection/test-analysis/b/5682156132106240\n\nSample build with failed test: https://ci.chromium.org/b/8668501104388031185\nAffected test(s):\n[://\\:blink_web_tests!webtest::fast/ruby#text-decoration.html](https://ci.chromium.org/ui/test/chromium/:%2F%2F%5C:blink_web_tests%21webtest::fast%2Fruby%23text-decoration.html?q\u003dVHash%3Ab57e93f9ea8ad996)\n\nIf this is a false positive, please report it at http://b.corp.google.com/createIssue?component\u003d1199205\u0026description\u003dAnalysis%3A+https%3A%2F%2Fci.chromium.org%2Fui%2Fp%2Fchromium%2Fbisection%2Ftest-analysis%2Fb%2F5682156132106240\u0026format\u003dPLAIN\u0026priority\u003dP3\u0026title\u003dWrongly+blamed+https%3A%2F%2Fchromium-review.googlesource.com%2Fc%2Fchromium%2Fsrc%2F%2B%2F8456548\u0026type\u003dBUG\n\nOriginal change\u0027s description:\n\u003e Keep wavy text decorations continuous across fragments\n\u003e\n\u003e Anchor the wavy pattern at the start of the decorating box instead of\n\u003e each fragment\u0027s own origin, so the wave phase no longer restarts at\n\u003e inline element boundaries like a nested \u003cem\u003e. Behind the default-on\n\u003e WavyDecorationContinuousPhase runtime feature as a kill switch.\n\u003e\n\u003e Bug: 41287729\n\u003e Change-Id: Ia6ec134cdab6bbb3d2f7f64b631bc499bd9f4a56\n\u003e Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8456548\n\u003e Commit-Queue: Helmut Januschka \u003chelmut@januschka.com\u003e\n\u003e Reviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\n\u003e Cr-Commit-Position: refs/heads/main@{#1714354}\n\u003e\n\nBug: 41287729\nNo-Presubmit: true\nNo-Tree-Checks: true\nNo-Try: true\nChange-Id: I4b5bb2b004bc749a841868b43fe1c4bc945efed6\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8536782\nReviewed-by: Andy Phan \u003candyphan@chromium.org\u003e\nCommit-Queue: Andy Phan \u003candyphan@chromium.org\u003e\nOwners-Override: Andy Phan \u003candyphan@chromium.org\u003e\nBot-Commit: rubber-stamper@appspot.gserviceaccount.com \u003crubber-stamper@appspot.gserviceaccount.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714737}\n"
    },
    {
      "commit": "71b4d5f0eb7628a5d5f7cd2ee868ce1b1b5dc010",
      "tree": "c65695763dfb47b4eff24ca48ff5d81a971326d2",
      "parents": [
        "15c04ca9d43b87c817fa74aeb5c7d9346bb8ca66"
      ],
      "author": {
        "name": "Tim van der Lippe",
        "email": "TimvdLippe@users.noreply.github.com",
        "time": "Thu Oct 08 17:11:11 2026"
      },
      "committer": {
        "name": "Simon Pieters",
        "email": "zcorpan@gmail.com",
        "time": "Fri Oct 09 00:48:19 2026"
      },
      "message": "Update relevant-mutations-lazy.html"
    },
    {
      "commit": "15c04ca9d43b87c817fa74aeb5c7d9346bb8ca66",
      "tree": "72eb06914a9438688c7393ce45e96a882efac8cc",
      "parents": [
        "b60c4b349d9d167bf354a40bc0d4cbed15174606"
      ],
      "author": {
        "name": "Tim van der Lippe",
        "email": "TimvdLippe@users.noreply.github.com",
        "time": "Tue Oct 06 08:42:03 2026"
      },
      "committer": {
        "name": "Simon Pieters",
        "email": "zcorpan@gmail.com",
        "time": "Fri Oct 09 00:48:19 2026"
      },
      "message": "Fix expectations for width attribute changes\n\nFollowing https://github.com/whatwg/html/pull/13033 that should\r\ntimeout instead of load, as no engine currently does that.\r\n\r\nAdditionally, this test flakes on Safari because all images are lazily\r\nloaded from the cache. To dedupe these cache hits, add a query\r\nstring to each of them to ensure they are all unique."
    },
    {
      "commit": "b60c4b349d9d167bf354a40bc0d4cbed15174606",
      "tree": "a499343a14a03239fe23fdb3b183732ddaa6cf4b",
      "parents": [
        "96c8bb279c61ec8045e9b246b7b9a3cc127ca1a4"
      ],
      "author": {
        "name": "Oriol Brufau",
        "email": "obrufau@igalia.com",
        "time": "Thu Oct 08 11:05:57 2026"
      },
      "committer": {
        "name": "Servo WPT Sync",
        "email": "32481905+servo-wpt-sync@users.noreply.github.com",
        "time": "Thu Oct 08 21:14:40 2026"
      },
      "message": "layout: Don\u0027t paint fragment of inline box containing a block-level\n\nWhen an inline box gets split into multiple fragments because it has a\na block-level descendant, no browser paints a box shadow for the\nfragment of the inline box that only contains the block-level.\n\nSigned-off-by: Oriol Brufau \u003cobrufau@igalia.com\u003e\n"
    },
    {
      "commit": "96c8bb279c61ec8045e9b246b7b9a3cc127ca1a4",
      "tree": "2ac064c5ed8f303024a720ab78d5cd40725cb78b",
      "parents": [
        "2810902e6a3a78789efe5de3376d4f082087041f"
      ],
      "author": {
        "name": "mxmgorin",
        "email": "102797145+mxmgorin@users.noreply.github.com",
        "time": "Thu Oct 08 13:56:28 2026"
      },
      "committer": {
        "name": "Servo WPT Sync",
        "email": "32481905+servo-wpt-sync@users.noreply.github.com",
        "time": "Thu Oct 08 20:19:11 2026"
      },
      "message": "webgl: Return null from getUniformLocation for uniform block members\n\nSigned-off-by: mxmgorin \u003c102797145+mxmgorin@users.noreply.github.com\u003e\n"
    },
    {
      "commit": "2810902e6a3a78789efe5de3376d4f082087041f",
      "tree": "1fc7b70aafd3210a9d474234fc827545b6015ddf",
      "parents": [
        "0988598e7f9b83cf35024de90f1ba9198abda092"
      ],
      "author": {
        "name": "David Liu",
        "email": "lcdavid@google.com",
        "time": "Thu Oct 08 15:43:58 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 18:13:42 2026"
      },
      "message": "[css-scroll-snap] Use scrollBy() in scroll-snap-type-pair-007\n\nscroll-snap-type-pair-007 relied on a synthesized touch fling, but\nflings generated through ChromeDriver don\u0027t reach the compositor, so\nthe test can\u0027t reliably exercise fling behavior in WPT.\n\nReplace the fling with an instant 2D scrollBy(). scrollBy() snaps with\na displacement DirectionStrategy, which exercises the same 2D\ncosine-similarity conflict resolution under scroll-snap-type: pair,\nsynchronously and without testdriver. The step is kept small so that\nboth candidates remain mutually visible and compete.\n\nThe test passes under run_wpt_tests.py, including 100/100 runs of\nheadless_shell_wpt on Windows Swarming bots, so remove its flaky Win\nexpectation.\n\nBug: 542706103\nChange-Id: I3f67f2399724431ea34a3a4470bddefb2aa64e8e\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8518797\nReviewed-by: Vladimir Levin \u003cvmpstr@chromium.org\u003e\nCommit-Queue: David Liu \u003clcdavid@google.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714538}\n"
    },
    {
      "commit": "0988598e7f9b83cf35024de90f1ba9198abda092",
      "tree": "8da4ef61fae4891fb5956d3d47165beb7ae0e8e2",
      "parents": [
        "e9d3a761e4514ff7b266982f617fa4bcea2f0e4c"
      ],
      "author": {
        "name": "Stephen McGruer",
        "email": "smcgruer@chromium.org",
        "time": "Thu Oct 08 15:43:44 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 18:13:35 2026"
      },
      "message": "Reorganize Payment Method Manifest WPT files by pipeline stage\n\nAlign Payment Method Manifest Web Platform Test filenames and test\ngrouping with the specification pipeline stages (PMI, PMM, and WAM):\n\n   - Rename wam-ingestion.https.window.js to\n     pmm-default-applications.https.window.js to reflect that it tests\n     validation and parsing of the default_applications member of the\n     Payment Method Manifest (parallel to\n     pmm-supported-origins.https.window.js).\n   - Merge the non-HTTPS default_applications tests from\n     wam-non-https.https.sub.window.js into\n     pmm-default-applications.https.window.js (using get_host_info() and\n     options.origin on createWebAppManifestUrl).\n   - Move the Web App Manifest credentials omission test into\n     fetch-options.https.window.js alongside the PMI and PMM credentials\n     omission tests.\n\nBug: 552832440\nChange-Id: If86cac3bc67c4aa3e3dd0b84a718e72d8003541d\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8480645\nCommit-Queue: Stephen McGruer \u003csmcgruer@chromium.org\u003e\nReviewed-by: Xuehui Chen \u003cxuehuichen@google.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714503}\n"
    },
    {
      "commit": "e9d3a761e4514ff7b266982f617fa4bcea2f0e4c",
      "tree": "ec42c818d97c02512a022bf1b523dff993f2ab82",
      "parents": [
        "43ef4ddccb4bfd1ca2194d0a9a7dc86f8b7ffb21"
      ],
      "author": {
        "name": "David Awogbemila",
        "email": "awogbemila@chromium.org",
        "time": "Thu Oct 08 14:40:12 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 18:13:27 2026"
      },
      "message": "Update animation when setting currentTime with null timeline\n\nWhen an animation has no timeline, setting currentTime leaves the\nanimation outdated without an active timeline to tick it. This can leave\nthe animation outdated until a later lifecycle phase (such as Paint)\nlazily queries its state, triggering an on-demand timing update and\nstyle invalidation mid-paint.\n\nThis CL eagerly updates the timing model and invalidates the effect in\nAnimation::setCurrentTime when timeline_ is null, matching the behavior\nin Animation::setTimeline.\n\nBug: 567645136\nChange-Id: I5b977331b3670a9b9d88e744d6a58049388a5868\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8517898\nCommit-Queue: David A \u003cawogbemila@chromium.org\u003e\nReviewed-by: Kevin Ellis \u003ckevers@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714449}\n"
    },
    {
      "commit": "43ef4ddccb4bfd1ca2194d0a9a7dc86f8b7ffb21",
      "tree": "3d2ab159a383559efac6a953f6253b2b5fbeb534",
      "parents": [
        "fc1f41278c3cd1be0dc6eae467a14bdb0ecf4c3e"
      ],
      "author": {
        "name": "Kevin Ellis",
        "email": "kevers@google.com",
        "time": "Thu Oct 08 14:39:58 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 17:15:35 2026"
      },
      "message": "Fix scrollLeft-of-scroller-with-wider-scrollbar\n\nThe test passed on content_shell but not headless_shell because\ncontent_shell disabled overlay scrollbars. The maximum value for\nscrollLeft is scrollWidth - clientWidth. When tested with overlay\nscrollbars enabled, clientWidth is non-zero, which affects the\nlimit.\n\nBug: 570397389\nChange-Id: Id0a012534e2b36b8ead3ee906e1ff1867561f830\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8527466\nReviewed-by: Rune Lillesveen \u003cfuthark@chromium.org\u003e\nCommit-Queue: Kevin Ellis \u003ckevers@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714448}\n"
    },
    {
      "commit": "fc1f41278c3cd1be0dc6eae467a14bdb0ecf4c3e",
      "tree": "d0fd6b839b656d667773031673af520c4ff63c9f",
      "parents": [
        "e7352ab6762e7cf7f473879e52737b6813886093"
      ],
      "author": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Thu Oct 08 07:21:49 2026"
      },
      "committer": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Thu Oct 08 17:12:27 2026"
      },
      "message": "Remove internals.markContextAsInsecure()\n\ninternals.markContextAsInsecure() turned a document created as a secure\ncontext into a non-secure one, which cannot happen otherwise: an API that\nrequires a secure context is either exposed or not. It also changed state only\nin its own process, so with site isolation other processes still saw a secure\ncontext.\n\nTests now get a real non-secure context from the WPT server, as localhost is\npotentially trustworthy. Tests that need nothing WebKit-specific become\nweb-platform tests:\n- orientation-event/device-orientation-events-unavailable-on-insecure-origins.html\n  is imported and replaces http/tests/events/device-orientation-motion-*.\n- speech-api/SpeechRecognition-non-secure-context.http.html is new and replaces\n  http/wpt/mediastream/speechrecognition-insecure.html.\n  SpeechRecognitionResultList is still exposed in non-secure contexts.\n- html/cross-origin-opener-policy/non-secure-to-secure-context-navigation.https.html\n  moves from http/wpt. Its popup now starts at\n  get_host_info().UNAUTHENTICATED_ORIGIN and navigates itself to the secure page.\n\nThe tests for the login status API, getGamepads() and geolocation\u0027s console\nmessage move to http/wpt and run from get_host_info().UNAUTHENTICATED_ORIGIN.\nThe login status test now checks navigator.setStatus() and\nnavigator.isLoggedIn() instead of navigator.setLoggedIn(), which no longer\nexists.\n\nFour tests are removed, as imported WPTs already cover them from a non-secure\ncontext:\n- fast/web-share/share-canShare-insecure.html, by web-share/canShare-insecure.http.html\n  and web-share/share-securecontext.http.html.\n- http/tests/notifications/notification-in-non-secure-context.html, by\n  notifications/permissions-non-secure.html.\n- http/tests/workers/worker-iframe-owner-isSecureContext.html, by\n  secure-contexts/basic-dedicated-worker.html.\n- http/wpt/crypto/historical.html, by WebCryptoAPI/historical.any.html.\n\nThis also removes the SecurityOrigin and Document setters that only the hook\nused.\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326672\n"
    },
    {
      "commit": "e7352ab6762e7cf7f473879e52737b6813886093",
      "tree": "8c2014f55a60850d5acede0418cba53c3274e8da",
      "parents": [
        "8ad1a3cfff8159fddd8018ffe8048fbb320a9228"
      ],
      "author": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Wed Oct 07 17:33:31 2026"
      },
      "committer": {
        "name": "Anne van Kesteren",
        "email": "annevk@annevk.nl",
        "time": "Thu Oct 08 17:12:00 2026"
      },
      "message": "Do not deserialize Window and DedicatedWorker-only types in other workers\n\nWebCodecs types, MediaStreamTrack, MediaStreamTrackHandle,\nMediaSourceHandle, RTCEncodedAudioFrame and RTCEncodedVideoFrame are\n[Exposed\u003d(Window,DedicatedWorker)], but posting one to a shared worker\nor service worker delivered it there. Use the generated exposure check\nfrom 322966@main for these serialization tags, through\nisInterfaceExposedInGlobalObject() from 322979@main, so that those\nmessages fail to deserialize and result in a messageerror event.\n\nThe interfaces\u0027 [EnabledBySetting] now also applies when deserializing.\n\nVideoFrame, AudioData, MediaStreamTrack and MediaSourceHandle already\nfailed to deserialize there whenever the message crossed processes, as\ntheir data is not encoded for IPC. A shared worker can share the page\u0027s\nprocess though, so that was not reliable. The new tests cover them too.\n\nWebKit-Bug: https://bugs.webkit.org/show_bug.cgi?id\u003d326689\n"
    },
    {
      "commit": "8ad1a3cfff8159fddd8018ffe8048fbb320a9228",
      "tree": "ab5ae998104f17273bf71ca65b03ed04a60c25c5",
      "parents": [
        "e8a0386e6c8ec97605ad9552d75eff44c129f05a"
      ],
      "author": {
        "name": "Leo Tenenbaum",
        "email": "ltenenbaum@mozilla.com",
        "time": "Thu Oct 08 13:47:51 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Thu Oct 08 16:46:24 2026"
      },
      "message": "Add helper functions for sending push messages in tests.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331371\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2077522\ngecko-commit: 17df242af303d69643901f203eda414076957949\ngecko-commit-git: 63dfc11b64974d916e069d8546623963412afa51\ngecko-reviewers: saschanaz\n"
    },
    {
      "commit": "e8a0386e6c8ec97605ad9552d75eff44c129f05a",
      "tree": "f02ab77585960f298ef20853d8d515414b3c8d75",
      "parents": [
        "88d9816e5022b8802a6bba34f3fd32ee0c2ee630"
      ],
      "author": {
        "name": "wpt-pr-bot",
        "email": "wpt-pr-bot@users.noreply.github.com",
        "time": "Thu Oct 08 05:13:27 2026"
      },
      "committer": {
        "name": "Sam Sneddon",
        "email": "me@gsnedders.com",
        "time": "Thu Oct 08 16:31:07 2026"
      },
      "message": "Automated update of CODEOWNERS\n"
    },
    {
      "commit": "88d9816e5022b8802a6bba34f3fd32ee0c2ee630",
      "tree": "4af9b6d415d841adf02c43afa5f3bc24558d4a2f",
      "parents": [
        "4c3ecfb79e5fa5afe249969a6185d6b8642ee061"
      ],
      "author": {
        "name": "Andreu Botella",
        "email": "abotella@igalia.com",
        "time": "Thu Oct 08 16:19:53 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Oct 08 16:19:53 2026"
      },
      "message": "Fix assertion message for block-ellipsis-036.html (#63416)\n\nThe previous assertion had been copied off of `block-ellipsis-033` and not updated to match the test."
    },
    {
      "commit": "4c3ecfb79e5fa5afe249969a6185d6b8642ee061",
      "tree": "e56a87ac6c7ede496373dc29658d9fe188d4cd4e",
      "parents": [
        "29099a8c15ed232af88aa20ca411dafe9f062e7d"
      ],
      "author": {
        "name": "Sampath Samaraweera",
        "email": "sampath.samaraweera@codimite.com",
        "time": "Thu Oct 08 12:59:02 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 16:17:44 2026"
      },
      "message": "Invalidate shapes\u0027 percentage `stroke-dashoffset` on viewport resize\n\nFollow-up to https://crrev.com/c/8361775, which added\n`stroke-dasharray` to the ComputeStrokeHasRelativeLengths() helper\nbut left out `stroke-dashoffset`.\n\nA shape whose only percentage-based stroke property is\n`stroke-dashoffset` was therefore never flagged as\nviewport-dependent, so the viewport-change handling in\nSVGContentContainer skipped re-laying it out and the dash phase\nkept its stale value until some unrelated relayout recomputed it.\n\nAdd the missing case to ComputeStrokeHasRelativeLengths(). The dash\noffset is already resolved against the current viewport at paint\ntime, in SVGLayoutSupport::ApplyStrokeStyleToStrokeData(), so\nflagging the dependency is all that is required.\n\nFixed: 560379373\nChange-Id: Ifa3a6128ef600637cf614a09f4b29b2b5ad3f1aa\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8423508\nReviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\nCommit-Queue: Fredrik Söderquist \u003cfs@opera.com\u003e\nReviewed-by: Kent Tamura \u003ctkent@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714371}\n"
    },
    {
      "commit": "29099a8c15ed232af88aa20ca411dafe9f062e7d",
      "tree": "aa54f417ab2292099ad15ca7cf5232174fdf644f",
      "parents": [
        "beba5cfdc940c47113a1f68d52ba9c1414c7725f"
      ],
      "author": {
        "name": "Helmut Januschka",
        "email": "helmut@januschka.com",
        "time": "Thu Oct 08 12:07:08 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 16:17:36 2026"
      },
      "message": "Keep wavy text decorations continuous across fragments\n\nAnchor the wavy pattern at the start of the decorating box instead of\neach fragment\u0027s own origin, so the wave phase no longer restarts at\ninline element boundaries like a nested \u003cem\u003e. Behind the default-on\nWavyDecorationContinuousPhase runtime feature as a kill switch.\n\nBug: 41287729\nChange-Id: Ia6ec134cdab6bbb3d2f7f64b631bc499bd9f4a56\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8456548\nCommit-Queue: Helmut Januschka \u003chelmut@januschka.com\u003e\nReviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714354}\n"
    },
    {
      "commit": "beba5cfdc940c47113a1f68d52ba9c1414c7725f",
      "tree": "6bc5d4e4bc644c03bf87781593c870c3a153e9f5",
      "parents": [
        "47b65690f1690ed993c9465d0e6703a290025a4b"
      ],
      "author": {
        "name": "Fernando Fiori",
        "email": "ffiori@microsoft.com",
        "time": "Tue Oct 06 21:49:20 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 16:17:28 2026"
      },
      "message": "Remove void element end tags from security and loading WPTs\n\nimg, input, link, meta, embed, source and area have no end tag. Writing\ntheir end tag anyway is a parse error, and the parser drops the tag, so\nthe source suggests a structure the document never had. This CL removes\nthese end tags from\nthird_party/blink/web_tests/external/wpt/content-security-policy and\nsome other WPT tests.\n\nBug: 542686202\nChange-Id: I943e45528f1a57d2cbad7aeb0e4c3803fcc8289b\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8226705\nReviewed-by: Stephanie Zhang \u003cstephanie.zhang@microsoft.com\u003e\nReviewed-by: Fernando Fiori \u003cffiori@microsoft.com\u003e\nCommit-Queue: Fernando Fiori \u003cffiori@microsoft.com\u003e\nAuto-Submit: Fernando Fiori \u003cffiori@microsoft.com\u003e\nCr-Commit-Position: refs/heads/main@{#1712686}\n"
    },
    {
      "commit": "47b65690f1690ed993c9465d0e6703a290025a4b",
      "tree": "12e972b5c089ec38e0db9ec6603942f383235585",
      "parents": [
        "0e6e43503b0b00c8a5c8a69b1e0f3c634b14da76"
      ],
      "author": {
        "name": "Daniel Clark",
        "email": "daniec@microsoft.com",
        "time": "Fri Oct 02 18:29:05 2026"
      },
      "committer": {
        "name": "jgraham",
        "email": "james@hoppipolla.co.uk",
        "time": "Thu Oct 08 16:12:09 2026"
      },
      "message": "Ensure page has focus at the start of the test\n"
    },
    {
      "commit": "0e6e43503b0b00c8a5c8a69b1e0f3c634b14da76",
      "tree": "5541e6159d0f7238520fdd9b87db5fd933578e48",
      "parents": [
        "8b75d8b975a2dbcc731281ac0f5128365b8061f5"
      ],
      "author": {
        "name": "Keith Cirkel",
        "email": "keithamus@users.noreply.github.com",
        "time": "Thu Oct 08 16:10:27 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Oct 08 16:10:27 2026"
      },
      "message": "HTML parser: support #description in html5lib .dat tests (#63407)\n\nA test may begin with a #description section, appended to its subtest name. Add descriptions to a few existing tests."
    },
    {
      "commit": "8b75d8b975a2dbcc731281ac0f5128365b8061f5",
      "tree": "1aa59367b01119c77cec61f7eb667c56f01bb720",
      "parents": [
        "da1355b3fc629f97f8194884ab113da1ba3c7990"
      ],
      "author": {
        "name": "Luke Warlow",
        "email": "lwarlow@igalia.com",
        "time": "Thu Oct 08 16:10:03 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Oct 08 16:10:03 2026"
      },
      "message": "Test moving element then using tree selectors (#63408)\n\nAlso test for moving an element into a display none tree."
    },
    {
      "commit": "da1355b3fc629f97f8194884ab113da1ba3c7990",
      "tree": "c20e3e6cab7c361d3b49acd83b349df962487b57",
      "parents": [
        "04f9780fbf73b1630810aad450edbe7841d228c7"
      ],
      "author": {
        "name": "Maksim Sadym",
        "email": "sadym@chromium.org",
        "time": "Thu Oct 08 10:30:00 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 12:07:00 2026"
      },
      "message": "[chromium-bidi] Speed up pointer actions in input.performActions\n\n- Speed up pointer click and move actions in input.performActions by\n  ~3.4x (reducing 1000 clicks from ~16.7s to ~4.9s).\n- Previously, every input.performActions call evaluated\n  navigator.platform via CDP, scheduled setTimeout(0) on zero-duration\n  ticks, and awaited rAF-aligned CDP mouseMoved commands before sending\n  mousePressed, stalling each click on 60Hz VSync (~16.67ms).\n- Lazily evaluate and cache the macOS platform check only for keyDown\n  actions, skip setTimeout(0) on zero-duration ticks, and pipeline\n  subsequent non-move actions behind zero-duration hover mouseMoved\n  commands to flush the renderer event queue immediately.\n- Remove stale SlowTests entries and Chromium-only timeout\u003dlong metadata\n  for bidi/input/perform_actions WPTs, and update the\n  release_actions/queue.py expectation baselines.\n\nBug: 411434092\nCq-Include-Trybots: luci.chromium.try:linux-webdriver-bidi-rel\nInclude-Ci-Only-Tests: chromium.linux:Linux Tests|webdriver_wpt_tests\nChange-Id: I9317f17c6ab70b96e65b1b1286f42b51929bacbf\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8522202\nAuto-Submit: Maksim Sadym \u003csadym@chromium.org\u003e\nReviewed-by: Nikolay Vitkov \u003cnvitkov@chromium.org\u003e\nCommit-Queue: Nikolay Vitkov \u003cnvitkov@chromium.org\u003e\nCr-Commit-Position: refs/heads/main@{#1714317}\n"
    },
    {
      "commit": "04f9780fbf73b1630810aad450edbe7841d228c7",
      "tree": "99865a36c58d731d117c287b782f098f49b19e79",
      "parents": [
        "63f1ac64740504b29d28130c1ed7b243dff2b700"
      ],
      "author": {
        "name": "Ibrahim Bendebka",
        "email": "ibrahim.bendebka@gmail.com",
        "time": "Thu Oct 08 10:29:49 2026"
      },
      "committer": {
        "name": "Blink WPT Bot",
        "email": "blink-w3c-test-autoroller@chromium.org",
        "time": "Thu Oct 08 12:06:52 2026"
      },
      "message": "Fix corner-shape auto outline doubled offset and radii\n\nWhen an element had both `corner-shape` and `outline: auto`,\nchanging `outline-offset` resulted in a doubled offset and radii.\n\nThis occurred because the rect and radii used to define the\ncontour\u0027s origin_rect, were already outset adjusted.\n\nThis CL calculate the origin_rect radii from\nGetFocusRingCornerRadii at zero offset.\n\nBug: 556780780\nChange-Id: Id0516d151d383312278a69b7af68ada1fec6f0be\nReviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8367406\nCommit-Queue: Jason Leo \u003ccgqaq@chromium.org\u003e\nReviewed-by: Noam Rosenthal \u003cnrosenthal@google.com\u003e\nReviewed-by: Fredrik Söderquist \u003cfs@opera.com\u003e\nCr-Commit-Position: refs/heads/main@{#1714279}\n"
    },
    {
      "commit": "63f1ac64740504b29d28130c1ed7b243dff2b700",
      "tree": "f9a748751c1c7100ded16e7755c6b20fee9f231a",
      "parents": [
        "c2375350396a13eedc5d227d9de64c51fd8e7d55"
      ],
      "author": {
        "name": "David Shin",
        "email": "dshin@mozilla.com",
        "time": "Thu Oct 08 02:17:38 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Thu Oct 08 12:02:07 2026"
      },
      "message": "Propagate relative selector search path when we find sibling standin.\n\nWe use the search path flags in elements to short-circuit :has invalidation.\nWhen we find the standin, the standin element should inherit that flag, so\nthat we don\u0027t mistakenly short circuit out of invalidation later.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D298320\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2035307\ngecko-commit: 13221bb0f205da65261ab5b0d2cce044e9a51af3\ngecko-commit-git: c542731375d22d0a21b346e353a42ceb5037c45e\ngecko-reviewers: firefox-style-system-reviewers, emilio\n"
    },
    {
      "commit": "c2375350396a13eedc5d227d9de64c51fd8e7d55",
      "tree": "7931879a0c31e49354343de9128cdf75e26fb43b",
      "parents": [
        "5317b6b4425281c30f63c7f025ca810c6274f506"
      ],
      "author": {
        "name": "Emilio Cobos Álvarez",
        "email": "emilio@crisal.io",
        "time": "Wed Oct 07 22:56:23 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Thu Oct 08 11:56:30 2026"
      },
      "message": "Don\u0027t create an unnecessary style scope from AddCounterChanges.\n\nThis is a bit sketchy over-all, but is enough to prevent the\nfirst-letter code from messing up the style scoping, and I think it\u0027s\nsound, because first-letter can never pull a whole inline or somesuch...\n\nThis is only an issue for that code because ::first-letter will create a\nframe for an arbitrarily deep text node (but just the text, which can\u0027t\nhave counters). So if it manages to create something for a text node\nthat\u0027s about  to go away we end up with a stale scope.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331349\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2076268\ngecko-commit: 89140e53922b7b6eace5194e5389fe0ddc2859cc\ngecko-commit-git: b0af5bf7cd945a4cdced2d13f554b9026931ca1b\ngecko-reviewers: layout-reviewers, dshin\n"
    },
    {
      "commit": "5317b6b4425281c30f63c7f025ca810c6274f506",
      "tree": "ca5b76e29ea53fbb35f999f697bf2f2d2e9c0842",
      "parents": [
        "c8525d333367e1db0161011bce29a3f8333943d7"
      ],
      "author": {
        "name": "Emilio Cobos Álvarez",
        "email": "emilio@crisal.io",
        "time": "Wed Oct 07 22:56:22 2026"
      },
      "committer": {
        "name": "moz-wptsync-bot",
        "email": "wptsync@mozilla.com",
        "time": "Thu Oct 08 11:56:30 2026"
      },
      "message": "Simplify nsGenConInitializer.\n\nNo need to create the list upfront, do it only when we get to initialize\nthe text frame.\n\nDifferential Revision: https://phabricator.services.mozilla.com/D331348\n\nbugzilla-url: https://bugzilla.mozilla.org/show_bug.cgi?id\u003d2076268\ngecko-commit: aab647729dbbc9997b6633066aec47cd3e43ba05\ngecko-commit-git: 84edf83684a29ceb7fbcbb1f3061dae64f830b2c\ngecko-reviewers: layout-reviewers, dshin\n"
    },
    {
      "commit": "c8525d333367e1db0161011bce29a3f8333943d7",
      "tree": "e892164c6078c589a72ecbb64144abd86f9076c1",
      "parents": [
        "0962bf0b291f0077095d4ba519194e6b535d79c0"
      ],
      "author": {
        "name": "Yoav Weiss",
        "email": "yoav.weiss@shopify.com",
        "time": "Thu Oct 08 11:45:24 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Oct 08 11:45:24 2026"
      },
      "message": "Add bounds to LoAF style and layout durations (#63399)"
    }
  ],
  "next": "0962bf0b291f0077095d4ba519194e6b535d79c0"
}
