feat(network): transport typed text-value postcondition observations - #270
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Seongho Bae <me@seonghobae.me>
|
RCA and exact-head repair: predecessor |
|
Parent synchronization on exact head |
Bind the live gap baseline to PR #270's current parent-synchronized head and preserve its transport-only maturity boundary.\n\nCommit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Writer lease RELEASED — root task 01a06c0f-b427-7830-b654-9addcdfe7aff. Published and read back 8eda969 against parent 3df2a63. Ordinary history-preserving adoption plus three test-first sender repairs completed. Local 11 focused and 147 Python tests, full Rust/fmt/check/strict Clippy/rustdoc and exact 100% production coverage pass (1346 functions, 14113 lines, 17928 regions, 1464 branches). Independent read-only review found no actionable issues; actual Edge screenshots of rustdoc and published commit inspected. CI 34076117534 jobs 101602453962 and 101602453789 are queued, not passing; no formal approval or merge claimed. Worktree /private/tmp/originweave-pr270-sync.AHRA8K and ignored results.tsv/coverage artifacts preserved. No source writer remains on this lease. Next dependent item: #271 response/value admission. |
Current parent adoption and sender repair — 2026-09-07
Published head:
8eda96915dbbe4cc617f834267c7464689c2844d. Independently resolved parent #269:3df2a631bacd7109b3982fdd7ac599d0bd92a589. Ordinary merge preserves both histories.Real loopback RED tests proved foreign-session dispatch, invalid-deadline pending registration, and reused-mask pending registration before the repair. The sender now reuses canonical session, deadline, connection-generation, and lifetime command-ID guards. Proven zero-write rejection retires only that request; ambiguous writes remain pending. Fixed observation source and child authority tests remain intact; result/value verification remains #271 work.
Local exact-head verification: 11 focused tests, 147 Python tests and compileall, formatting, workspace/all-target check, full Rust tests and compile-fail docs, strict Clippy, rustdoc, and exact production coverage: 1,346/1,346 functions; 14,113/14,113 lines; 17,928/17,928 regions; 1,464/1,464 branches. Coverage artifact SHA-256:
7748d42c541140314995ffa2087b3aca87d52875f98a6ffa36614a0453b30260. CodeGraph is healthy. Independent read-only review found no actionable findings; it is not formal approval.Actual Edge screenshot inspection of generated API documentation verified readable guard descriptions and no clipping/overlap. This is documentation evidence, not browser-agent runtime acceptance.
Exact-head CI run 34076117534 is now terminal success on unchanged
8eda96915dbbe4cc617f834267c7464689c2844d. This repository-native GREEN validates only this exact active-PR tree. It does not transfer to #271, establish an independent approval, prove real-browser post-conditions, or establish protected-main/release acceptance.Active ruleset requirements and the still-open parent stack remain separate gates. Keep Draft; no merge, self-approval, gate bypass, tag or release is claimed.
Historical dossier — preserved verbatim, superseded where noted
The following describes earlier heads. In particular, its blanket frame-write pending-retention statement is superseded by the proven-zero-write versus ambiguous-write distinction above.
Partial implementation of #28, stacked directly on PR #269 branch
feat/webdriver-bidi-type-text-postcondition-commandexact head7854394266d3f292e779193c01413a34f6798d7c.Buyer-visible boundary
This Draft transports the fixed product-owned WebDriver BiDi
script.callFunctiontext-value observation command across the reviewed direct WebDriver BiDi/RFC 6455 boundary. The public send API consumes an exactWebDriverBiDi+SemanticObservationprotocol-use proof, reconstructs the command from live admitted-node authority immediately before dispatch, registers the command id before the first possible remote side effect, and emits one bounded masked WebSocket text frame.Wrong protocol family or capability, stale/wrong browser-context authority, duplicate correlation, and invalid frame deadlines fail closed. A frame-write failure after registration deliberately leaves the command id outstanding because partial or complete remote execution is ambiguous; it is never silently reused. The transport does not retry, reconnect, select an alternate destination, accept caller-supplied script source/sandbox, grant browser/policy/destination/secret authority, or infer text-entry success.
Test-first lineage
Exact RED head
3ba1d61e48a2542c835f41d79ebc7913673ef38cadded a realistic loopback TCP → RFC 6455 integration regression requiringsend_webdriver_bidi_text_value_observationbefore that production boundary existed. CI run33459143984, Rust contracts job99705411429, failed at workspace compilation on that RED head. No failed predecessor evidence is promoted to the implementation head.The canonical branch then added the typed send error, immediate-use authority reconstruction, semantic-observation capability enforcement, command correlation, bounded frame write, public export, and hostile/failure regressions for wrong capability, wrong protocol family, wrong external context, duplicate correlation, and invalid frame deadline.
Historical exact-head evidence
Historical head
191a14535219ea8033777fa4c970efb281b62418against base7854394266d3f292e779193c01413a34f6798d7cpassed local Rust/Python/coverage checks; predecessor native CI33459335836was terminal success on still earlier480d411011120b40d88beec3942aee049541b71d. These are lineage evidence only and do not replace the current exact-head success above.Stack / authority boundary
Keep Draft while #269 and its ancestors remain Draft. #271 owns correlated result admission and intended-text post-condition verification; dispatch and protocol acknowledgement alone are not success. Protected-main
AGENTS.mdand live GitHub governance remain authoritative. No workflow/ruleset/secret, force-history, approval, merge, tag, release or publication mutation belongs to this PR.