Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 41ffde255367141f07eae35a0da2f9c8bfc87c44
      
https://github.com/WebKit/WebKit/commit/41ffde255367141f07eae35a0da2f9c8bfc87c44
  Author: Jessica Lee <[email protected]>
  Date:   2026-09-28 (Mon, 28 Sep 2026)

  Changed paths:
    M LayoutTests/platform/ios-site-isolation/TestExpectations
    M Source/WebCore/loader/FrameLoader.h
    M Source/WebKit/UIProcess/WebPageProxy.cpp
    M Source/WebKit/WebProcess/WebPage/WebFrame.cpp
    M Source/WebKit/WebProcess/WebPage/WebPage.cpp
    M Source/WebKit/WebProcess/WebPage/WebPage.h
    M Source/WebKit/WebProcess/WebPage/WebPage.messages.in

  Log Message:
  -----------
  [Site Isolation] 
imported/w3c/web-platform-tests/fetch/api/basic/keepalive.any.html is a 
constant failure.
https://bugs.webkit.org/show_bug.cgi?id=325316
rdar://188427760

Reviewed by Alex Christensen.

This patch fixes 3 issues that prevent unload handlers from running when a 
cross-site iframe is removed with
site-isolation. The test depends on this - the iframe's unload handler sends a 
keepalive fetch that stores a token
on the server, and fetch/api/basic/keepalive.any.html checks for that token.

The first is that WebPageProxy::didDestroyFrame() disconnected the iframe 
before sending WebPage::FrameWasRemovedInAnotherProcess.
Thus, the iframe's process never received this message and never started the 
removal sequence
(WebPage::frameWasRemovedInAnotherProcess() → WebFrame::removeFromTree()) that 
dispatches unload events. The
fix is to re-order these so that the UIProcess broadcasts this message before 
disconnecting the iframe.

The second is that unload events are not dispatched in the removed frame's 
process. When all frames are in a single process,
removing the iframe is routed through FrameLoader::detachFromParent(), calling 
closeURL() which dispatches unload events.
closeURL() is not called in the site-isolated equivalent pathway. The fix is to 
add closeURL() to the site-isolated equivalent
function WebFrame::removeFromTree() so unload events are now dispatched.

The third is that the UIProcess teardown of the remote iframe process and the 
iframe process's completion of frame removal
(removeFromTree()) execute in parallel. This resulted in termination of 
iframe's process before it could dispatch unload events.
The fix is to keep the iframe process alive until removeFromTree() completes. 
(This follows the approach of
WebFrameProxy::commitProvisionalFrame(), which keeps the old process alive 
until LoadDidCommitInAnotherProcess replies.)

The relevant test is 
imported/w3c/web-platform-tests/fetch/api/basic/keepalive.any.html.

* LayoutTests/platform/ios-site-isolation/TestExpectations:
* Source/WebCore/loader/FrameLoader.h:
* Source/WebKit/UIProcess/WebPageProxy.cpp:
(WebKit::WebPageProxy::didDestroyFrame):
* Source/WebKit/WebProcess/WebPage/WebFrame.cpp:
(WebKit::WebFrame::removeFromTree):
* Source/WebKit/WebProcess/WebPage/WebPage.cpp:
(WebKit::WebPage::frameWasRemovedInAnotherProcess):
* Source/WebKit/WebProcess/WebPage/WebPage.h:
* Source/WebKit/WebProcess/WebPage/WebPage.messages.in:

Canonical link: https://commits.webkit.org/322072@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to