Skip to content

[OriginWeave] Canonicalize sandbox-enabled MV3 browser workflow and thin caller #1792

Description

@seonghobae

Owner-path defect

OriginWeave's governed-browser source and repository contracts now require real pinned Chromium execution with sandboxing enabled, but the current repository-local workflow authority is inconsistent with that contract and product PRs are not authorized to repair .github/** themselves.

Fresh exact evidence:

Historical exact-head #43 evidence proved the pinned archive contains a usable chrome_sandbox and that root:root + mode 4755 + CHROME_DEVEL_SANDBOX completed repeated real Chromium MV3 passes. That predecessor execution is technical feasibility evidence only; it is not current-head GREEN or current workflow authorization.

Chromium's current Ubuntu developer-build guidance warns that --no-sandbox disables critical security features and should never be used for open-web browsing. Chromium's SUID sandbox guidance shows the raw-build helper shape (chown root:root, chmod 4755, CHROME_DEVEL_SANDBOX), while current Ubuntu 23.10+ guidance also permits a narrowly reviewed AppArmor/user-namespace configuration. Therefore the central design may use the setuid helper or a demonstrably equivalent sandbox-capable mechanism, but it must not weaken sandboxing.

Required central architecture

Create or extend a canonical reusable workflow in ContextualWisdomLab/.github for OriginWeave's pinned Chromium/MV3 evidence, with an exact-SHA thin caller in OriginWeave. Do not copy product-domain browser policy into .github; central ownership is limited to trusted workflow/toolchain/evidence mechanics.

The reusable workflow should own at minimum:

  1. immutable Chrome for Testing / ChromeDriver identity and checksum verification;
  2. a sandbox-capable Ubuntu execution setup that preserves Chromium sandboxing without --no-sandbox or global disabling of Ubuntu's user-namespace security;
  3. least-privilege permissions, no provider/model credentials, bounded network behavior, deterministic artifact retention, and exact caller-head binding;
  4. execution of OriginWeave-owned runner entry points rather than copying browser-domain logic into the central repository;
  5. typed distinction between runner unavailable, browser startup/sandbox failure, product-contract failure, cancellation, and successful current-head evidence;
  6. immutable action pins and workflow-contract tests protecting the helper/setup and caller SHA;
  7. enough inputs to support the existing downloads/compatibility Agent Task lane and the Repair fragile OpenCode approval reasons from evidence #245 Web Audio privacy evidence without creating independent workflow authorities for each product feature.

RED acceptance

On the current protected-main workflow shape, a deterministic contract must demonstrate that sandbox-preserving OriginWeave browser execution requires setup not supplied by the workflow. A queued/unassigned job is incomplete evidence and does not substitute for this source-level RED.

Also retain a fixture proving that --no-sandbox, empty/disabled sandbox configuration, missing helper/AppArmor allowance, wrong Chrome/ChromeDriver identity, or an unverified caller revision cannot become successful browser-security evidence.

GREEN acceptance

Non-goals

  • Restoring --no-sandbox.
  • Globally disabling Ubuntu AppArmor user-namespace restrictions.
  • Moving OriginWeave browser policy/domain truth into .github.
  • Treating runner queue starvation as workflow GREEN.
  • Self-approval, bypass, force-push, gate weakening, or predecessor-check reuse.

Coordinate with .github#712 / .github#1531 for runner/queue control and OriginWeave#212 for leaf adoption. Keep those causal classes separate.

Activity

  1. added
    priority: criticalImmediate blocker, P0, urgent deadlock, or critical incident
    bugSomething isn't working
    type: bugDefect or incorrect behavior
    on Sep 7, 2026
  2. seonghobae commented on Sep 21, 2026

    @seonghobae
    ContributorAuthor

    OriginWeave owner-path handoff — fresh 2026-09-21 evidence supersedes this issue body's old #43/protected-main snapshot without changing central ownership.

    Canonical reusable browser-evidence implementation is now PR #1857 at exact a6d16c0f36e31da539ee98d550277d2169e33514, Draft / mergeable on protected .github/main@e6334e229581a918e2f22de18733b76fa65d7e71. Its effective owner surface remains the reusable workflow, doctoring, and workflow-contract test; Chrome/ChromeDriver 150.0.7871.129 is intentionally preserved as that generation's immutable historical qualification identity. Fresh exact-head workflow reads: SAST 35450581183 = success; Security Scan 35450581194, Python Security 35450581337, and CodeQL PR 35450581222 = terminal cancelled. Cancellation is non-acceptance, not GREEN.

    There is also a new current-Stable fact relevant to the next versioned generation. Google Chrome Releases records desktop Stable 153.0.8010.52/.53 (Windows/Mac) and 153.0.8010.52 (Linux) on 2026-09-17. Chrome for Testing availability refreshed at 2026-09-21T07:32:07Z now lists Stable 153.0.8010.52 (r1681091) with HTTP 200 Chrome, ChromeDriver, and headless-shell assets across Linux arm64/linux64, macOS arm64/x64, and Windows 32/64. Thus the previous matching-asset availability uncertainty is gone for the Ubuntu/Linux64 lane.

    Do not mutate #1857's Chrome 150 receipt in place. The next owner generation should freeze exact 153.0.8010.52 archive SHA-256 receipts, retain sandbox/no-secrets/exact-caller constraints, obtain its own exact-head security/review acceptance, land normally, and only then permit an OriginWeave consumer pin + complete page-observed replay. OriginWeave#212 has been currentized to this boundary and remains the leaf adoption ledger.

    Primary sources: https://chromereleases.googleblog.com/2026/ and https://googlechromelabs.github.io/chrome-for-testing/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    maintenancepriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions