// Static hosts without COOP/COEP headers: install the in-repo isolation shim, wait until it controls // this page, then load again. An isolated load clears the retry count, so a later load that comes up // unisolated (e.g. a hard reload, which bypasses the service worker) tries again; two failed tries // in a row stop, so a host where the shim cannot work never loops. // window.__coiGate resolves when the app may boot: at once when isolated (or when the shim cannot help: // insecure context, no service workers, retries used up, registration failed), and never when this page // is about to be replaced by the isolated load, so a phone does not build the 277k-gate machine twice. // If the re-navigation has not happened 4 s later, or the shim has not got that far within 8 s (a // registration that never settles), the app boots unisolated (the §13.2 fallback path) and stays: the // worker, once active, isolates the next visit instead of interrupting this one.…