But it looks like all four points of the security model (including #4 that you've quoted) were retained. Luckily, Chrome is more aggressive on popups than ever, so there's less likelihood, but it's not yet bulletproof.
I agree it looks like Chrome's implementation is not matching this spec. I'll look into if we can tighten this up.