Skip to content

feat(network): bind navigation events to active subscriptions - #264

Draft
seonghobae wants to merge 83 commits into
feat/webdriver-bidi-navigation-unsubscribefrom
feat/webdriver-bidi-navigation-subscription-admission
Draft

feat(network): bind navigation events to active subscriptions#264
seonghobae wants to merge 83 commits into
feat/webdriver-bidi-navigation-unsubscribefrom
feat/webdriver-bidi-navigation-subscription-admission

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Current pointer receipt parent adoption

Exact head 433957117ad9e29b26715b062f5adcc9789744ba ordinarily incorporates #263 4868d3e9f19133ac3382ee8532878aef27468893, preserving original child 6f331a5b220349a1aaa1b1841d5e8ec027b9ad49 and all contributor histories. Only two pointer production modules change: sender connection-bound registration is combined with the existing monotonic typed dispatch, and replies require the existing sealed reader.

Real replacement pointer success and error both failed at 637fd97d (0/2). Ordinary merge 92e576c8 now passes all 13 focused tests, including original-reply recovery and unrelated-request retention. Child subscription registry/session/intent provenance, raw/typed isolation, consuming unsubscribe ownership and same-connection teardown are preserved. Generic registration cannot mint a subscription receipt; the stronger child success/error precedence remains intact.

Full locked Rust 1.97.1 formatting, all-target workspace check, workspace tests and compile-fail contracts, strict Clippy, warning-denying rustdoc, 145 Python contracts, compileall, CodeGraph sync and diff checks pass. Unchanged pinned coverage enforcement passes at 100%: 1282/1282 functions, 13461/13461 lines, 17140/17140 regions, 1440/1440 branches. Artifact coverage-parent-43395711.json SHA-256 e102bda45da886bc3138b981dac73f4239e2f6e5cd893688f10ed72b1f5af771; experimental branch instrumentation warning retained.

Independent read-only preservation review found no actionable findings at this exact head; it is not counted approval. Documentation distinguishes historical parent-only deferrals from the stronger current child. Exact-head CI 34066516991 (Rust 101576116581, coverage 101576116719) and MV3 34066516992 (job 101576116667) are queued; no hosted pass is claimed. Actual in-app browser screenshot of the published 43395711 traceability section shows readable wrapping, the historical-parent heading and current-child safeguards without observed clipping or overlap. This verifies GitHub documentation presentation, not OriginWeave product-browser acceptance. Keep Draft: pointer outbound authority, browser authentication, action causality, protected foundation recovery and release acceptance remain incomplete. No protected merge, workflow/ruleset/secret change or history rewrite.

Historical child checkpoints — evidence applies only to their named heads

Current source checkpoint — registry-to-transport session provenance

Exact head 6f331a5b220349a1aaa1b1841d5e8ec027b9ad49, unchanged #263 base 3f22de94b63da83eaa8b5b1270912b21a3ecd006; Draft. Normal publication preserves b4702cd and all previous contributor history.

The original real-loopback regression at b4702cd was executed locally and failed because registry session A dispatched on transport session B. Hosted CI34031977586 later confirmed that failure and supplied-test formatting differences; its MV3 run34031977597 passed. The repair reuses the canonical external-session mapping for a read-only check before pending-command registration or command bytes. Unknown, foreign, malformed, retired and re-registered mappings are covered. The actual socket test now requires the typed mismatch, zero pending commands and zero bytes. Registry ownership, private command intent, connection-bound receipt/teardown and ambiguous-write retention remain intact; matching text does not authenticate the browser process.

An intermittent pointer fixture failed during seed-Pong timeout cleanup before pointer dispatch. A channel now completes that setup before simulated peer closure, preserving the actual ambiguous-write assertions. No production frame semantics, dependency or gate was changed.

Complete exact-head locked Rust 1.97.1 workspace/all-feature tests, formatting, all-target check, strict Clippy, warning-denying rustdoc, 145 Python contracts, compileall, CodeGraph and diff checks pass. Pinned nightly2026-08-01 coverage and the unchanged verifier pass: 1282/1282 functions, 13455/13455 lines, 17136/17136 regions, 1440/1440 branches. Artifact SHA-256 b85acd79c3e3a3a49561b9148b6aafadc26cd292a542ec74ef2b523e88c42eaa. Earlier two-line/three-region diagnostic gaps remain recorded; the existing unit error-contract array now covers the new variant. Independent read-only review found no actionable issue; it is not counted approval.

Proposed ADR 0107, doctoring and CHANGELOG record the rationale and limits. Fresh exact-head CI 34035628391 (Rust 101493050566, coverage 101493050411) and MV3 34035628337 (job 101493050208) are queued. Actual Edge screenshots of this exact head's PR body and Checks page show readable wrapping, distinct status controls and no observed clipping or overlap. This is GitHub presentation evidence, not OriginWeave product-browser acceptance. Protected-main integration, real Chromium product acceptance, eligible counted approval and release evidence remain separate. No force push, merge, tag, release or workflow/ruleset change.

Preserved historical checkpoints

Current source checkpoint — subscription teardown ownership and provenance

Exact head 7fb93e77b800f27187a5c02333298cc31a025bd6, unchanged #263 base 3f22de94b63da83eaa8b5b1270912b21a3ecd006; Draft. Normal publication preserves both complete contributor histories and all earlier repairs.

The existing non-cloneable subscription receipt now transfers into teardown. Construction ends its availability for event admission, including on failure. The command retains the original connection identity, rejects foreign dispatch before correlation or wire bytes, and admits success/error only through the existing connection-bound reader and matching sent correlation. No revocation registry, dependency or quality-gate change is introduced. Already admitted observations are not retroactively revoked; acknowledgment does not prove event drainage, browser cleanup, authentication or action causality.

Reproduced failures and local acceptance

  • Lifetime RED 2c45cea8: actual received receipt remained usable for admission after borrowed teardown construction. The repaired API's runnable compile-fail example reports exactly E0382 for receipt reuse; original RED remains in history.
  • Transport RED ce6f6fd4: foreign send emitted 91 actual masked bytes; foreign success/error consumed the original pending command and prevented its genuine reply.
  • All three migrated transport regressions, eight preserved unsubscribe failures, fourteen admission cases and the escaped-identifier round trip pass. Generic unbound registration cannot manufacture an acknowledgment. Real servers are joined before decisive assertions.
  • Complete locked Rust 1.97.1 workspace/all-feature formatting, check, strict Clippy, rustdoc and tests pass, including three network doctests. All 145 Python contracts, compileall, CodeGraph sync and diff checks pass.
  • Unchanged pinned coverage passes exactly: 1279/1279 functions, 13421/13421 lines, 17106/17106 regions, 1438/1438 branches. SHA-256 277c5bc0a17f16966a8eb388d54e4e172be36356d7dead5bbead9ed53ad8cff6. The unstable branch-instrumentation warning remains explicit.
  • Independent read-only source review found no actionable defect. This is not counted GitHub approval.

Hosted and delivery boundary

New exact-head CI 34031281825 and MV3 34031281812 are queued (Rust 101481131938, coverage 101481131907, MV3 101481131930); no hosted GREEN is claimed. Visual inspection of this new published head remains pending: the actual browser reported a locked Mac that automatic unlock could not unlock. Prior-head screenshots are not reused as evidence. Parent-first protected integration, #195/#279 prerequisite work, real Chromium acceptance and release evidence remain separate.

Proposed ADR 0107, doctoring, API baseline, unsubscribe traceability and CHANGELOG record scope and alternatives. No merge, tag, release, workflow/ruleset change, force push or approval substitution.

Preserved prior checkpoint evidence

Current command-response freshness repair

Exact published head: 805051527cf95e14ba126c9dd3159db86d190224; exact base #263: 3f22de94b63da83eaa8b5b1270912b21a3ecd006. The PR remains Draft. Normal publication preserves both complete contributor histories through bd29f405 and 52cff969.

Reproduced defect and bounded repair

Four actual-socket lifecycle cases first fail at 92fd0b07: a retained success for a completed, retired, replacement-registry or unread buffered command can complete a newly sent same-ID subscription and create new admission. The error-first variants also fail at 15aea15e. Three additional actual-wire REDs demonstrate raw-to-typed, typed-to-raw and reused-ID bypasses. A compile-fail contract also showed that the public pre-upgrade socket borrow could clone the underlying stream.

The existing established-connection owner now retains an O(1) typed-command high-water mark and an exclusive raw-text/typed mode. All five typed senders use the same gate before I/O. The first typed ID may be zero; subsequent IDs must strictly increase, including after completion, retirement, replacement correlation, reader reconstruction and Pong traffic. Out-of-order replies remain valid for distinct outstanding IDs. This is an explicit local policy, not a W3C requirement; a new connection is needed for a new raw/typed lane or after ID exhaustion. No lifetime-sized tombstone collection, new dependency or generic transport implementation was added.

The nonconsuming BiDi socket borrow is removed; consuming handoff remains. The real locally revoked-socket test now lives within the owning unit module rather than reopening the alias. Existing masking-key and ambiguous-write tests retain their distinct failure paths using Pong and fresh IDs. Buffered fixtures synchronize actual server emission and accept EOF/reset only before any second-command byte.

Exact-head local verification

  • Rust 1.97.1 formatting, locked workspace/all-target/all-feature check, strict Clippy, warning-denying rustdoc, complete workspace/all-feature tests, all 145 Python contracts, compileall, CodeGraph and diff checks pass.
  • All 22 affected admission/frame tests and the added real public opening-deadline test pass within the complete suite; no security test is skipped.
  • Unchanged pinned nightly-2026-08-01 branch coverage is exactly 1279/1279 functions, 13409/13409 lines, 17087/17087 regions, 1436/1436 branches. Artifact SHA-256: 64a62b1e03ee3ed3d62654a3227495e82b7ff93357038ae146d8584c581ac060. The separate unstable branch-instrumentation warning remains.
  • Earlier buffered fixture BrokenPipe/reset failures are preserved. At e6c02cf, all stable gates passed but coverage missed one region: the ordinary-library copy lacked public error propagation while the unit copy lacked invalid-timeout coverage. LLVM's per-instantiation maxima did not union those source regions. The final real public deadline case covers the ordinary copy, with no production or verifier change and no restored socket alias.
  • Independent read-only source review is advisory and does not constitute counted GitHub approval.

Hosted, visual and delivery boundaries

The preceding 10f138f8 native CI 34026519860 and real MV3 34026519878 are now verified terminal success. They do not validate this new head. Fresh exact-head native CI 34029687813, Rust 101476824185 and coverage 101476824305, is queued. Fresh MV3 34029687816, job 101476824298, is queued. No predecessor result is transferred.

Post-publication visual inspection in actual Edge verified the rendered exact 80505152 PR body and separate Checks page, matching base, Draft status and all three queued job identities. Desktop screenshots show readable wrapping, distinct headings and status controls without observed clipping or overlap. This is GitHub presentation evidence, not an OriginWeave product-browser acceptance test. The real one-nanosecond deadline test passed locally; portability beyond executed targets remains subject to fresh hosted execution.

The repair does not authenticate registry-to-browser-session/transport association or repair unsubscribe receipt lifetime/transport provenance. Browser action causality, end-to-end Chromium product acceptance, #195/#279 foundation integration, protected-main delivery and release eligibility remain unfinished. ADR 0107 remains Proposed. No workflow, ruleset, security gate, approval identity, merge, tag, release or forced history update is part of this slice.

Preserved predecessor evidence at 10f138f

Current original-registry ownership repair

Exact published head: 10f138f8787d596e8b556fe50c9e4e52bc1295b7; exact base #263: 3f22de94b63da83eaa8b5b1270912b21a3ecd006. The PR remains Draft. Normal fast-forward publication from 2a9fdc54 was verified; both complete contributor histories through bd29f405 and 52cff969 remain ancestors.

Four actual-socket REDs at b3ffeac9 showed that another real registry with colliding local IDs could send an original command, admit its original receipt, admit its original-connection event, or mutate another document using an observation correctly admitted against the original registry. The last path did not require matching external context text. The earlier c41e737b fixture compile error is not behavioral RED evidence.

The repair uses one opaque core-owned standard-library allocation witness, retained through the existing command, binding and subscribed observation. Ownership is checked before sender correlation/I/O, receipt admission, event replay insertion and the shared document-mutation sink; origin binding already uses that sink. Cloning the witness and moving the original registry remain valid. Dropping the original owner does not permit a replacement registry to reuse its retained identity. Existing command identity, receive provenance, live context/epoch, no-write/ambiguous-write and contributor regression contracts remain intact. No new transport, global identifier scheme, dependency, workflow, exclusion or quality threshold is introduced. ADR 0107 remains Proposed.

Exact final-head local verification

  • All four new actual-socket regressions pass; the complete workspace run includes the 15 affected admission/send-failure tests and the existing origin, unsubscribe and crossed-connection tests. All 145 Python contracts pass without skips; compileall, CodeGraph and diff checks pass.
  • Rust 1.97.1: actual pinned formatting; locked workspace/all-target/all-feature check; complete workspace/all-feature tests; strict all-target/all-feature Clippy; warning-denying all-feature rustdoc all pass.
  • Pinned nightly-2026-08-01 workspace/all-feature branch coverage and the unchanged numerical verifier pass at 1278/1278 functions, 13371/13371 lines, 17056/17056 regions, 1434/1434 branches. Artifact SHA-256: 9f5b4942d6a040a83f09593a2b81406c44bc9d2b402fa995a95294ce8e9cbb7e. The unstable branch-instrumentation warning remains.
  • Earlier e686b3a0 missed one line/three regions in the core diagnostic unit copy. The existing diagnostic test now exercises the real owner-drop mismatch; 33787617 then reached 100% but its test expect_err failed strict Clippy. The final head uses the established collection/cardinality assertion style. Those failures are preserved, not hidden or transferred as final acceptance.
  • Independent read-only review found no actionable authority, lifetime, public-construction, contributor-preservation or documentation finding. This is not counted GitHub approval.

Hosted and unreleased boundaries

Fresh exact-head native CI 34026519860 is queued: Rust 101468348712, coverage 101468348775. Fresh MV3 34026519878, job 101468347302, is also queued. Local results and predecessor hosted runs do not establish these checks.

The witness binds the registry that constructed the command; it does not authenticate that registry's browser-session association with the transport. Actual same-connection resend freshness, unsubscribe lifetime/transport provenance, action causality, real Chromium acceptance, #195/#279 foundation integration, protected-main delivery and release eligibility remain unproven. No approval substitution, merge, tag, release, workflow/ruleset change or history rewrite occurred.

Preserved predecessor integration evidence at 2a9fdc5

Current integrated subscription receive-provenance repair

Exact published head: 2a9fdc5418b9af10353cdad0f6f6470655bf457d; exact base #263: 3f22de94b63da83eaa8b5b1270912b21a3ecd006. The PR remains Draft. Normal fast-forward publication from 52cff969 was verified after explicit writer handoff; both the complete remote lineage and previously private bd29f405a6c927b2f7d1c437dccbfb8bcec424f1 are now ancestors of this shared head.

The integrated change rejects subscription success/error replies and navigation events received on a different connection before consuming pending commands or changing document/replay state. The original connection can still complete its reply or admit the same event. It retains the remote actual typed-send malformed/unknown/error fixtures, event diagnostics, rustdoc and source contract together with private original-connection recovery, unchanged-document tests and authentic receipt redaction checks. The receipt always retains its existing private generation; one shared validator enforces generation presence and equality. No new authority registry, transport implementation, dependency, workflow or deadline is added.

Exact local verification

  • Test-first predecessors bc2e69d5 and 918c4ebe preserve the real crossed-connection failures on 43d3b5a3; earlier results remain predecessor evidence.
  • All 26 focused subscription/unsubscribe/transport socket tests are retained in the complete passing workspace test run. All 145 Python repository contracts pass with no skips.
  • Rust 1.97.1: actual cargo fmt --all --check; locked workspace/all-target/all-feature check, test, and clippy -- -D warnings; RUSTDOCFLAGS='-D warnings' cargo doc --locked --workspace --all-features --no-deps; Python compileall and diff check pass on this exact head.
  • Pinned cargo +nightly-2026-08-01 llvm-cov --locked --workspace --all-features --branch --json --output-path coverage.json and the unchanged coverage verifier pass: 1273/1273 functions, 13317/13317 lines, 16984/16984 regions, 1432/1432 branches. Artifact SHA-256: f7e71e6fd67723688535053c389b4ff718c4563b403924af462848d3d51b541f. The separate unstable branch-instrumentation warning remains.
  • Independent read-only comparison found no actionable lost contributor delta or authority regression. It is not a counted GitHub approval.

Hosted and product boundaries

Fresh exact-head CI 34024499232 has Rust contracts 101462946602 and Production coverage 101462946523 queued, not green. Earlier hosted runs and local results do not substitute for these new checks.

Caller-supplied registry/transport identity, actual-resend freshness when the same connection reuses an id, unsubscribe transport/lifetime provenance, action causality, real Chromium acceptance, protected-main integration and release eligibility remain unproven. The #195/#279 prerequisite and current review/branch policy still apply. No approval, merge, tag, release or workflow/ruleset mutation occurred.

Preserved predecessor description at shared 52cff96

Current bounded repair — subscription receive provenance

Exact head: 52cff96954c3fec7b8cda5409e4560e970bfcbdf; exact base #263: 3f22de94b63da83eaa8b5b1270912b21a3ecd006. The PR remains Draft and mergeable. No workflow, ruleset, dependency, deadline, downstream-stack, merge, tag, or release mutation is part of this slice.

Test-first commit bc2e69d52c0d95b1abc3ff69dd0433c0349254b2 records two real TCP/RFC 6455 crossed-connection defects on predecessor 43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e: a session.subscribe receipt sent on verified connection A could be consumed from verified connection B, and an admitted subscription established on A could accept a browsingContext.navigationCommitted event read on B. This is a source-proven transport-provenance gap, not a browser exploit claim and not a parent-adoption regression.

The bounded repair reuses the existing connection owner rather than introducing another authority. The typed subscription sender records the established connection's private process-local generation together with the existing private Arc command-instance identity before any possible network side effect. WebDriverBiDiNavigationCommittedSubscriptionResult::parse_and_correlate now accepts only WebDriverBiDiReceivedTextMessage, compares the exact receive generation before consuming correlation, and retains that generation in the typed receipt. Active event admission likewise accepts only a connection-bound received message and rejects a generation mismatch before registry revalidation or event parsing. Public generic correlation registration can provide neither the private command identity nor connection provenance.

The earlier command-instance repair remains intact: unsent same-id bindings, identical-field replacement commands, cross-registry numeric collisions, and receipt reconstruction through generic re-registration remain fail closed. Existing frame-owner semantics are intentionally preserved: invalid deadlines fail before registration, a provably local no-write MalformedFrame retires only the new typed subscription, and an ambiguous write failure leaves correlation outstanding.

The fixture migration is deliberately asymmetric. Subscription receipts and subscription-backed events use WebDriverBiDiWebSocketMessageReader; existing unsubscribe production still parses its receipt through the older raw-message boundary. The unsubscribe command/receipt transport provenance limitation therefore remains explicitly unresolved and is not claimed fixed by this PR slice.

A fresh exact-source diagnostic of predecessor 8ebcc6131a5dd6bf0b4720c2f1ff8d40d1cc39f8 reproduced two quality failures: cargo +1.97.1 fmt --all --check failed in five affected test files, and the unchanged numerical coverage verifier failed only two line/region gaps while functions and branches were fully covered. Follow-up commit da4a11f0c350308769f473eb32784609e0172429 shares connection-generation validation rather than duplicating the unreachable defensive missing-generation arm; 701fcaad7080b8ca99aa6e742254af6b3de2992f covers the public EventConnectionMismatch diagnostic. Commits 6fca12b4, d2769a96, fa015c82, f87f0952, and 52cff969 apply only formatting corrections to the five reproduced test-file offenders. The remote typed-send fixtures, connection rustdoc, and source contract remain preserved.

Current exact-head native CI is run 34023932180; Rust contracts job 101461440021 and Production coverage job 101461439818 are queued with no runner/steps yet. They are non-passing pending evidence, not GREEN. Prior-head local/hosted results are historical only and are not transferred to this head. The unpublished private bd29f405a6c927b2f7d1c437dccbfb8bcec424f1 lineage and any local ordinary integration proof remain separate evidence: they are not present on this shared head and do not establish combined or hosted acceptance.

Remaining explicit boundaries include actual resend with stale same-id response, original-binding use against another caller-supplied registry/transport association, unsubscribe receipt/transport provenance, action/browser causality, real-browser acceptance, and the existing #195/#279 protected-foundation prerequisites. No formal approval is inferred from an empty review state.

Historical lineage retained

The prior command-instance RED 73f11de2232060ac7680e188db88ef7609123296 and repair 43d3b5a3a2b5ce4f51a93d1152a0ee82620f4f3e established exact sent-command identity. The ordinary parent-adoption RED 44c44b46dd4eabf8f09adc4e1da7c608f3bbf1be and adoption head cf0f2452ea0612106f1076dcb2df58c7d6428943 preserved #263 transport/correlation/teardown behavior while retaining this child's admission/document-transition contracts. Those results remain lineage evidence, not current acceptance.

Keep Draft while the stack/foundation prerequisites and exact-head acceptance remain unresolved.

@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

The unchanged current-parent loopback regression cannot compile on the admission predecessor: its connection-bound reader types and transport-mismatch rejection variant are absent. Record the inherited RED contract before ordinary adoption; do not replace it with raw assembled response evidence.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Ordinarily adopt #263 at3f22de94b63da83eaa8b5b1270912b21a3ecd006 after unchanged received-response provenance regression reproduced compiler RED. Preserve all parent transport/correlation/teardown semantics and the existing active-subscription child implementation and tests.

Nine focused loopback tests,144 Python contracts, full Rust1.97.1 gates and1271/13244/16919/1428 production coverage all pass. Retain Draft, existing event-provenance limits and separate protected foundation/workflow prerequisites; no workflow, dependency, deadline or acceptance-gate change.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Reproduce same-id context substitution and receipt reconstruction after public correlation re-registration over real loopback transport.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep private command-instance identity in existing bounded correlation state. Reject unsent same-id bindings, cross-registry numeric collisions and receipt reconstruction through generic re-registration; preserve frame-failure and typed-response semantics.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Require a foreign connection to preserve outstanding subscription commands and prevent foreign event text from creating state-changing observations.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
…ence

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Wait for server emission without reading the response so the buffered replay case cannot race client closure. Preserve the buffered-message threat and no-second-write assertions.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
A rejected resend drops a socket with unread data, so macOS may reset the peer. Peek for the first additional byte before parsing; only EOF or reset before any byte satisfies non-emission. Keep real second-command parsing for the vulnerable branch.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Retain the private real revoked-socket case and cover error propagation through the public library without restoring a cloneable socket alias.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Use an actual sent subscription and received event to prove that borrowing its receipt for teardown leaves active event admission constructible.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>

Copy link
Copy Markdown
Contributor Author

Registry-to-transport session-provenance writer acquired — 2026-09-06 11:58 UTC

This scheduled OriginWeave writer acquires one bounded #264 source slice at exact 7fb93e77b800f27187a5c02333298cc31a025bd6, unchanged #263 base 3f22de94b63da83eaa8b5b1270912b21a3ecd006, Draft. Prior #264 unsubscribe and #238 evidence writers are explicitly released.

Scope is the still-open registry→verified-WebDriver-session transport association only. First reproduce with a real loopback WebSocket that a subscription bound to registry session A can currently be emitted on an established transport whose endpoint evidence is correlated to a different WebDriver session B. The expected guard is before command correlation and before any command-frame byte. Preserve the current non-cloneable receipt, connection-generation, monotonic command-id and unsubscribe repairs; do not claim browser-process authentication, action causality or post-condition proof from this slice.

No #238 writer. No workflow/ruleset/secret/merge/tag/release mutation, no force history update, and no predecessor hosted result transfer. Writer release will be explicit after publication/verification or a proven defer.

Copy link
Copy Markdown
Contributor Author

Registry→BiDi-session provenance writer RELEASED — test-first checkpoint b4702cd503fa3f721e0d1f44b355563753dac0a2 — 2026-09-06 12:16 UTC

Normal branch publication is verified on unchanged #263 base 3f22de94b63da83eaa8b5b1270912b21a3ecd006; #264 remains Draft. This checkpoint intentionally contains RED test only, not a claimed fix.

New real-loopback integration file crates/originweave-network/tests/webdriver_bidi_navigation_subscription_registry_transport_provenance.rs constructs registry session A, establishes an actual RFC 6455 transport whose endpoint is correlated to different valid UUID session B, and requires rejection before correlation registration and before the first command-frame byte. Static source tracing confirms current WebDriverBiDiNavigationCommittedSubscriptionCommand::send revalidates registry identity/context and records connection generation but does not compare the registry session's external WebDriver id with established.transport_evidence().verified_peer().session_id() before correlation/I/O.

This is protocol-session provenance, not browser-process authentication. The 2026-09-03 WebDriver BiDi Editor's Draft defines a BiDi session's set of session WebSocket connections, states each WebSocket connection is associated with at most one BiDi session, and accepts /session/<session id> only by associating the connection with that active session. The smallest causal repair, after executable RED is observed, is a read-only registry session-external-id revalidation using the existing canonical session_by_external mapping, surfaced through BrowserAuthorityRegistry, then invoked before subscription correlation/wire I/O. Do not create a second session registry or mutate registry state from transport text.

Executable RED is presently blocked before checkout by the organization runner-admission incident: CI 34031977586 jobs Rust 101483061658 and coverage 101483061462, plus MV3 34031977597, remain queued with no runner. Fresh OriginWeave inventory was 17 queued / 0 in-progress; canonical queue RCA handoff is .github#712 comment 5559135943, with repository-local separation in #279 comment 5559102938. No rerun/no-op churn, predecessor evidence transfer, workflow/ruleset mutation, or gate weakening was performed.

Because AGENTS requires observing the relevant failure before production repair, this writer stops at the published test-first checkpoint rather than converting static diagnosis into unexecuted GREEN. Writer explicitly RELEASED. A successor may reacquire once an actual runner executes this head (or another policy-compliant execution backend yields the real failure), then implement the root-causal guard, exact error contract, focused/full Rust/Python/coverage verification, docs/ADR/CHANGELOG, and fresh exact-head hosted evidence.

seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Registry-session provenance source writer RELEASED — 2026-09-06 13:19 UTC

Current source checkpoint — registry-to-transport session provenance

Exact head 6f331a5b220349a1aaa1b1841d5e8ec027b9ad49, unchanged #263 base 3f22de94b63da83eaa8b5b1270912b21a3ecd006; Draft. Normal publication preserves b4702cd and all previous contributor history.

The original real-loopback regression at b4702cd was executed locally and failed because registry session A dispatched on transport session B. Hosted CI34031977586 later confirmed that failure and supplied-test formatting differences; its MV3 run34031977597 passed. The repair reuses the canonical external-session mapping for a read-only check before pending-command registration or command bytes. Unknown, foreign, malformed, retired and re-registered mappings are covered. The actual socket test now requires the typed mismatch, zero pending commands and zero bytes. Registry ownership, private command intent, connection-bound receipt/teardown and ambiguous-write retention remain intact; matching text does not authenticate the browser process.

An intermittent pointer fixture failed during seed-Pong timeout cleanup before pointer dispatch. A channel now completes that setup before simulated peer closure, preserving the actual ambiguous-write assertions. No production frame semantics, dependency or gate was changed.

Complete exact-head locked Rust 1.97.1 workspace/all-feature tests, formatting, all-target check, strict Clippy, warning-denying rustdoc, 145 Python contracts, compileall, CodeGraph and diff checks pass. Pinned nightly2026-08-01 coverage and the unchanged verifier pass: 1282/1282 functions, 13455/13455 lines, 17136/17136 regions, 1440/1440 branches. Artifact SHA-256 b85acd79c3e3a3a49561b9148b6aafadc26cd292a542ec74ef2b523e88c42eaa. Earlier two-line/three-region diagnostic gaps remain recorded; the existing unit error-contract array now covers the new variant. Independent read-only review found no actionable issue; it is not counted approval.

Proposed ADR 0107, doctoring and CHANGELOG record the rationale and limits. Exact-head CI 34035628391 is now terminal success on this unchanged head: Rust contracts 101493050566 completed success after Python repository contracts, formatting, workspace check/tests, strict Clippy and API docs; Production coverage 101493050411 completed success after measurement and exact-coverage enforcement. MV3 34035628337 / job 101493050208 is also terminal success, including hardened-runner undeclared-egress blocking, exact Chrome-for-Testing download and the real MV3 compatibility fixture. Actual Edge screenshots of this exact head's PR body and Checks page show readable wrapping, distinct status controls and no observed clipping or overlap. These exact-head hosted results and presentation evidence do not establish OriginWeave product-browser acceptance, eligible counted approval, protected-main integration or release. No force push, merge, tag, release or workflow/ruleset change.

Hosted-evidence refresh — 2026-09-06 20:00 UTC: the earlier queued wording above was refreshed only after REST readback of the unchanged exact head and terminal workflow/job results. No source/docs/ref mutation or predecessor evidence transfer occurred.

Root task 01a06c0f-b427-7830-b654-9addcdfe7aff holds no source/docs writer after this source release. Later #265/#238 work is separate and is not modified by this #264 evidence refresh.

Acquisition history

Registry-session provenance source writer ACQUIRED — 2026-09-06 12:54 UTC

Root task 01a06c0f-b427-7830-b654-9addcdfe7aff reacquires after verified release5559140277. Exact #264 head b4702cd, base3f22de94b63da83eaa8b5b1270912b21a3ecd006. Local Rust1.97.1 execution of webdriver_bidi_navigation_subscription_registry_transport_provenance now confirms real RED: 0 passed/1 failed, exit101, registry session A unexpectedly dispatched on transport session B. No production fix yet.

Scope: reuse canonical registry external-session mapping for read-only validation before subscription correlation/I/O, typed error and realistic tests, necessary fixture alignment without deleting assertions, docs/CHANGELOG and unchanged complete quality/coverage gates. No #265 mutation, workflow/ruleset change, merge/release or forced history. One source writer active; docs lease5559184232 released.

…patch

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>

seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Hosted-evidence PR-state writer RELEASED — 2026-09-06 20:04 UTC

Fresh readback keeps #264 Draft at exact 6f331a5b220349a1aaa1b1841d5e8ec027b9ad49, unchanged #263 base 3f22de94b63da83eaa8b5b1270912b21a3ecd006. Coordination comment 5559331330 now records exact-head CI 34035628391 terminal success with Rust contracts 101493050566 success and Production coverage 101493050411 success, plus MV3 34035628337 / 101493050208 terminal success with the real pinned Chrome-for-Testing fixture.

No source/docs/ref/workflow/ruleset/security-gate change, no #238/#265 takeover, no merge/tag/release or approval substitution occurred. The PR body itself still contains the older queued sentence; replacing that large body safely would require a complete-body mutation and current connector retrieval is truncated, so this run did not risk deleting preserved historical checkpoints. The corrected released coordination checkpoint is readback-verified. No #264 writer is retained.

seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Writer lease RELEASED — root task 01a06c0f-b427-7830-b654-9addcdfe7aff; no source/docs writer retained.

Published and readback-verified #264 433957117ad9e29b26715b062f5adcc9789744ba, base #263 4868d3e9f19133ac3382ee8532878aef27468893, remains Draft. Test-first RED 637fd97 (0/2), ordinary merge 92e576c, final docs 4339571. All 13 focused, full locked stable workspace gates, 145 Python contracts, compileall, CodeGraph and unchanged pinned coverage pass: 1282 functions, 13461 lines, 17140 regions, 1440 branches, each 100%. Coverage SHA-256 e102bda45da886bc3138b981dac73f4239e2f6e5cd893688f10ed72b1f5af771. Independent read-only review found no actionable findings; not counted approval.

Actual in-app screenshot of the exact published traceability section shows readable wrapping and historical/current boundaries without observed clipping or overlap. This is GitHub presentation evidence, not product-browser acceptance. CI34066516991 and MV334066516992 were queued at exact-head readback. Updated complete PR body retains all historical checkpoints. No merge, tag, release, force rewrite, workflow/ruleset/secret mutation or quality-gate weakening.

Acquisition history

Writer lease ACTIVE — root task 01a06c0f-b427-7830-b654-9addcdfe7aff. Acquiring sole source writer in existing isolated /private/tmp/originweave-pr264-registry-binding.ZQ23D1 at verified6f331a5b220349a1aaa1b1841d5e8ec027b9ad49 after all prior writers released. Scope: test-first ordinary adoption of published #2634868d3e9f19133ac3382ee8532878aef27468893. Replay parent pointer replacement-response regression first; preserve child registry identity, external-session mapping, monotonic command IDs/raw-typed isolation, consuming unsubscribe ownership and all contributor tests. No wholesale parent-file replacement, force rewrite, workflow/ruleset/secret mutation, protected merge or release. Full focused/workspace/coverage and actual visual inspection required; advisory reviewer is read-only. Existing coverage artifacts retained.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
…replies

Preserve the child registry and command identity, monotonic dispatch, consuming unsubscribe ownership and all existing assertions. Combine parent connection-bound pointer correlation with write_command_frame. Retain parent generic registration rejection with child-specific error precedence and unrelated-command isolation.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
…ards

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>

Copy link
Copy Markdown
Contributor Author

OriginWeave hourly writer acquires one bounded #264 PR-state/evidence-only slice at unchanged exact head 433957117ad9e29b26715b062f5adcc9789744ba, exact parent #263 4868d3e9f19133ac3382ee8532878aef27468893, Draft. Latest source lease 5562770321 is explicitly RELEASED and no later #264 writer is present.

Fresh hosted evidence has materially changed from the queued publication checkpoint: CI 34066516991 is terminal success (Rust contracts 101576116581, Production coverage 101576116719), and Manifest V3 Compatibility 34066516992 / 101576116667 is terminal success after hardened-runner egress and the real pinned Chrome for Testing fixture. Scope is public evidence correction only. The PR body contains a very large preserved historical checkpoint tree, so this slice will not replace/truncate it through an incomplete body read. No source, parent, workflow/ruleset/secret, approval, Draft/Ready, protected-main, tag or release mutation. Explicit release follows this current-evidence checkpoint.

Copy link
Copy Markdown
Contributor Author

#264 PR-state/evidence writer RELEASED at unchanged exact head 433957117ad9e29b26715b062f5adcc9789744ba, parent #263 4868d3e9f19133ac3382ee8532878aef27468893, Draft. Current exact-head hosted proof is now public: CI 34066516991 Rust 101576116581 and coverage 101576116719 terminal success; MV3 34066516992 / 101576116667 terminal success with hardened egress and real pinned-Chrome fixture. No source/body truncation, workflow/ruleset/secret, approval, protected merge, tag or release mutation; no #264 writer remains.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant