Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
bb88035
test(browser): require PID-safe browser crash evidence
seonghobae Aug 13, 2026
7c094ab
feat(browser): prove PID-safe Agent Task browser crash teardown
seonghobae Aug 13, 2026
b32bd3b
test(browser): require idempotent crash driver cleanup
seonghobae Aug 13, 2026
665b8a4
test(browser): bound pidfd exit race in crash evidence
seonghobae Aug 13, 2026
5aaaa68
fix(browser): tolerate browser crash process exit races
seonghobae Aug 13, 2026
ec40365
fix(browser): restore canonical runner formatting
seonghobae Aug 13, 2026
791fee2
test(browser): cover procfs ESRCH during crash identity read
seonghobae Aug 13, 2026
a249607
fix(browser): normalize procfs ESRCH as process exit
seonghobae Aug 13, 2026
8f87e85
test(browser): require exact crash root exit evidence
seonghobae Aug 13, 2026
f45a637
fix(browser): bind crash detection to exact process exit
seonghobae Aug 13, 2026
d4b175d
test(browser): prove unreaped crash termination boundary
seonghobae Aug 13, 2026
add43cb
test(browser): reject stale pidfd crash identity
seonghobae Aug 14, 2026
7e218fc
test(browser): distinguish pidfd exit from signal delivery
seonghobae Aug 14, 2026
b30c9fa
fix(browser): observe crash termination through pidfd
seonghobae Aug 14, 2026
43d3919
docs: record exact browser crash termination evidence
seonghobae Aug 14, 2026
6e28faa
chore(stack): absorb corrected shared-teardown prerequisite
seonghobae Aug 18, 2026
a73f0c2
chore(stack): absorb corrected crash-recovery prerequisite
seonghobae Aug 18, 2026
7953814
test(browser): fail closed on unexpected crash cleanup errors
seonghobae Aug 19, 2026
c66edac
fix(browser): narrow crash session cleanup failures
seonghobae Aug 19, 2026
890e01f
test(browser): reproduce partial crash cleanup response
seonghobae Aug 19, 2026
fd96b44
fix(browser): tolerate truncated post-crash cleanup response
seonghobae Aug 19, 2026
cb49d4c
fix(browser): restore crash runner after bounded cleanup patch attempt
seonghobae Aug 19, 2026
dd45158
fix(browser): tolerate truncated post-crash cleanup response
seonghobae Aug 20, 2026
9e3d499
Merge a73f0c2b0d9e88df3df7fcbc963226e029940eed into dd45158f230420b75…
seonghobae Aug 20, 2026
6f6291a
test(browser): retain terminal startup fail-closed contract
seonghobae Aug 23, 2026
885c879
fix(browser): reconcile crash recovery with live teardown prerequisite
seonghobae Aug 23, 2026
e0e449d
test(browser): bind crash sampling to exact root identity
seonghobae Aug 23, 2026
239a7b2
fix(browser): preserve root identity across crash sampling
seonghobae Aug 23, 2026
d8b3780
test(browser): reproduce crash driver teardown timeout escape
seonghobae Aug 23, 2026
b1cdf30
fix(browser): retain crash driver teardown timeout evidence
seonghobae Aug 23, 2026
633796c
test(browser): reproduce process-wide pidfd mock leakage
seonghobae Aug 23, 2026
73ea492
fix(browser): restore process-wide pidfd mocks
seonghobae Aug 23, 2026
4f03d45
Merge branch 'test/agent-task-browser-crash-recovery-evidence' into t…
seonghobae Aug 24, 2026
0575554
Merge pull request #151 from ContextualWisdomLab/test/agent-task-brow…
seonghobae Aug 24, 2026
056bc41
Merge 0575554f78809268585900e1d54011784ec9e7ee into 53a929246cf5c3616…
seonghobae Aug 24, 2026
2d9572c
Merge 056bc413906fdba3f27a112fdfddb997aa474c19 into 962e179b53ed0342f…
seonghobae Aug 25, 2026
33e46d5
test(browser): fail closed on unknown crash cleanup errors
seonghobae Aug 27, 2026
e37dccc
fix(browser): preserve fail-closed crash cleanup errors
seonghobae Aug 27, 2026
d7660ae
Merge remote-tracking branch 'origin/test/agent-task-forced-close-sha…
seonghobae Sep 4, 2026
b604570
Merge current #147 into browser crash evidence
seonghobae Sep 5, 2026
0a8009b
Merge current #147 ancestry into browser crash evidence
seonghobae Sep 5, 2026
bded4fc
fix: retain Chromium sandbox in browser-crash trials
seonghobae Sep 5, 2026
5742d00
test(browser): expose bounded crash failure stage
seonghobae Sep 5, 2026
bf5adac
fix(browser): retain bounded crash failure diagnostics
seonghobae Sep 5, 2026
08eab99
test(browser): lock crash reason vocabulary
seonghobae Sep 5, 2026
b4a0797
fix(browser): keep JSON crash reason distinct
seonghobae Sep 5, 2026
4b763f0
test(mv3): preserve primary crash failure evidence
seonghobae Sep 5, 2026
c81732a
fix(mv3): preserve primary browser crash diagnostics
seonghobae Sep 5, 2026
2d0b3c9
test(mv3): cover secondary crash teardown evidence
seonghobae Sep 5, 2026
3d11ddd
fix(test): retain cleanup-only exception identity
seonghobae Sep 5, 2026
8f34ad9
fix(test): exercise real driver teardown classifier
seonghobae Sep 5, 2026
e1f4e76
docs(changelog): preserve primary crash diagnostics
seonghobae Sep 5, 2026
ce6a260
test(browser): require sandboxed real-browser evidence paths
seonghobae Sep 5, 2026
0135984
fix(browser): keep every real-browser evidence lane sandboxed
seonghobae Sep 5, 2026
2323ff5
fix(browser): retain bounded startup failure evidence
seonghobae Sep 8, 2026
5a86b28
test(browser): require bounded ChromeDriver process diagnostics
seonghobae Sep 8, 2026
19998d6
fix(browser): retain bounded ChromeDriver startup diagnostics
seonghobae Sep 8, 2026
2b8e0e2
test(browser): require verbose ChromeDriver diagnostics
seonghobae Sep 8, 2026
0e320aa
test(browser): cover text-mode diagnostic doubles
seonghobae Sep 8, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ All notable changes to OriginWeave are documented in this file. The format follo

## [Unreleased]

- ChromeDriver `session not created` responses now retain a typed `session_not_created` failure and only the allowlisted `sandbox_unavailable` or `unknown` startup reason; raw driver-controlled response text remains excluded from browser-crash evidence.
- Browser-crash trials no longer disable Chromium's sandbox. Rejected session startup remains one failed attempt with driver and temporary-profile cleanup, without an unsandboxed retry; live pinned-browser acceptance is still required.
- Browser-crash failure evidence now preserves the first causal browser failure when session cleanup or ChromeDriver teardown also fails, retains secondary cleanup only as bounded exception-type fields, and excludes raw exception text from the emitted artifact. Cleanup-only failures remain fail-closed as primary failures.

### Added

- Kept the inherited protocol-failure cleanup checks executable after shared-deadline integration by observing the correct cleanup path for ordinary and forced-close trials; all failure, cleanup and diagnostic-redaction assertions remain intact.
Expand Down Expand Up @@ -42,6 +46,7 @@ All notable changes to OriginWeave are documented in this file. The format follo

### Changed

- Controlled browser-crash compatibility evidence now credits a crash only after the exact PID/start-time identity is signalled through a revalidated Linux pidfd and that same pidfd becomes readable within the bounded deadline; generic WebDriver transport failures no longer substitute for process-termination proof, while sampled Chromium process-set teardown remains a separate recovery boundary and the pidfd runtime contract remains mandatory on Linux CI.
- Separated logical origin authority from resolved network destination authority; an origin grant no longer implies permission to connect to every resolver result.
- Separated resolved-address authorization from direct transport evidence; an approved IP now becomes a usable stream only after the operating system reports the exact requested IP and port.
- Separated exact TCP peer proof from authenticated TLS service identity; an observed peer becomes an authenticated HTTPS stream only after explicit-root, fixed-time, SAN-bound WebPKI verification over that same stream.
Expand Down
10 changes: 10 additions & 0 deletions docs/doctoring.md
Original file line number Diff line number Diff line change
Expand Up @@ -124,6 +124,16 @@ At #147 `af1b98ba377c73b88baa9633e2232e7f76e76f36`, all six parent review-eviden

The existing test now specifies each lane's actual observer, return value and exact arguments. Ordinary trials keep the individual `False` result. Forced-close trials inject `(False, False)` from the shared observer and require `(321, 654, ((321, 654),))`, preserving root-only capture rather than inventing a complete descendant set. Every existing failed-trial, profile-cleanup, live-root, driver-termination, error-type and redaction assertion remains. No production code, deadline, retry, failed denominator or coverage gate changes. This repair does not address the separate ordinary-pass two-deadline finding or prove real Linux/pinned-Chromium acceptance.

### Browser-crash sandbox conformance

PR #148 adopts the current #147 parent `3dff28d9bf2dd27b72507e39979d51b8bf140fb4` by ordinary merge, retaining the crash/pidfd delta and all six inherited cleanup-evidence regressions. A new regression executes the actual outer crash trial and intercepts its session-start request: before the repair it fails because that request disables the Chromium sandbox. Removing that one crash-lane argument restores the existing sandbox invariant without introducing a configuration switch or fallback path.

The same regression requires one failed startup attempt, driver reaping and actual temporary-profile removal. It preserves browser executable selection and never credits the failed startup as a successful crash trial. The existing PID-safe signal/exit observers, sampled-process checks and trial denominator are unchanged. Other launch lanes retain their separate owner repairs; this child must not be interpreted as complete runner-wide sandbox integration. Mocked launch requests prove the control-flow contract, not that a real Chromium binary started with its sandbox active. Linux pidfd tests and exact-head pinned-Chromium compatibility remain separate acceptance evidence; macOS skips are not passes.

ChromeDriver session creation is also an evidence boundary. A structured `session not created` response is retained as a typed `session_not_created` failure. Only the reviewed `No usable sandbox` diagnostic maps to `sandbox_unavailable`; every other driver-controlled message maps to `unknown`. Raw response text, executable/profile paths and arbitrary diagnostics remain excluded, so the next pinned-browser run can distinguish the sandbox-helper case without admitting untrusted ChromeDriver prose into CI evidence. This classification does not install the helper, retry startup, disable the sandbox or make cleanup equivalent to browser success.

Supplemental verification used the existing Colima Linux kernel `6.8.0-117-generic` and Python `3.12.3`, without installing dependencies or changing VM configuration. All 247 Python contracts execute there with no skips, including the three real pidfd cases skipped on macOS: killed-but-unreaped child, non-terminating signal and stale identity. Initial host-path discovery failed because this VM does not expose the host worktree. The first streamed archive then added AppleDouble `._*.rs` files, causing two TLS source-read errors. A fresh export of only Git-tracked paths with `COPYFILE_DISABLE=1 tar --no-xattrs --no-acls --no-fflags` removes that packaging artifact at its producer; no test filter or source exception was added. Source and regression-file SHA-256 hashes match across hosts. This proves the supplemental Linux contracts, not pinned-Chromium execution, hosted approval or release acceptance.

## References

Amazon Web Services. (n.d.). *Set up the Amazon EKS Pod Identity Agent*. Retrieved August 6, 2026, from https://docs.aws.amazon.com/eks/latest/userguide/pod-id-agent-setup.html
Expand Down
Loading
Loading