Report the restored document's identity on back/forward cache commit
Component: WebCore Frame Loading | 63846dd
When a navigation is served from the back/forward cache rather than as a fresh load, FrameLoader::commitProvisionalLoad() calls dispatchDidCommitLoad() before cachedPage->restore() swaps the frame's Document to the cached one. Any code in dispatchDidCommitLoad() that reads state off the frame's current document therefore reads the outgoing document's data. The UI process consumes that data — through WKFrameInfo._documentIdentifier, securityOrigin, PageLoadState::origin() and WebDriver BiDi — as its answer to "what document is this frame showing right now".
This commit introduces BackForwardCacheCommitData to carry the restored document's identifier, security origin and COOP/COEP policies explicitly through FrameLoader::dispatchDidCommitLoad(), following the same pattern already used for hasInsecureContent, usedLegacyTLS and wasPrivateRelayed. WebLocalFrameLoaderClient::dispatchDidCommitLoad() then reports the restored document's identity rather than the outgoing one's.
Significance
The author flags this as a Site Isolation blocker: the UI process will use the committed document identifier to decide whether an incoming web-process message applies to the document currently displayed. Today the stale identity has no visible user-facing consequence, but once that mechanism ships an incorrect identifier here becomes an authorization bug rather than an API-accuracy nicety.
Audit directions
The pattern is a commit-time notification that fires before the state transition it is describing has happened. Narrow: enumerate the rest of what dispatchDidCommitLoad() and its client implementations read off the frame's current document, and check each against the bfcache ordering — the fields already plumbed explicitly (hasInsecureContent, usedLegacyTLS, wasPrivateRelayed) mark the ones someone has already found. Wider: any UI-process-visible identity value derived at a lifecycle callback rather than passed into it inherits the ordering question; the interesting set is every value the UI process later uses to decide whether a message applies to the thing currently displayed. Widest: identity reported by a callback whose ordering relative to the state swap is an implementation detail will eventually be wrong in one of the two orderings — the durable fix shape is passing the value in, which is exactly what this commit does. Code-review tell: a client-notification method that calls frame->document() to describe the load it is announcing.