Skip to content

[Browser Session/BiDi ACL] Bind current lifecycle authority to presentation command planning #314

Description

@seonghobae

Gap and current owner

The Browser Session foundation introduced a non-caller-mintable lifecycle authority, but the product still needs a safe ACL from current live aggregate authority into the version-qualified originweave-bidi presentation planner. A public constructor or conversion from a retained PresentationMutationAuthority snapshot would reopen the authority gap: authority retained across epoch advance, navigation invalidation, destruction, transport loss, recovery, or session end could be planned after it became stale.

Historical #313 was merged into the #229 branch lineage; it is not the current Browser Session authority surface. The active deterministic Browser Session foundation is #317, and the active protocol-specific ACL/proof implementation lane is #316. Keep this issue open until that current lineage reaches executable exact-head acceptance and protected integration.

Browser Session remains lifecycle/policy authority; WebDriver BiDi remains an adapter. This issue does not own browser transport/sandbox mechanics, Keyverse, EgressWeave, contextual-orchestrator, Wardnet, download persistence, or real-browser release acceptance.

Required invariant

A BiDi presentation witness may be produced only from authority that the live BrowserSession aggregate has revalidated as current at the point of adapter use. The validation proof must be non-caller-constructible and bound to the owning aggregate/incarnation/context generation so stale or foreign authority cannot reach command planning or port I/O.

Raw BrowserSessionId, BrowsingContextId, DisposableIsolationId, protocol navigation id, or a retained PresentationMutationAuthority alone is insufficient. Command acknowledgement is not proof that presentation state was applied, restored, or destroyed.

Standards/runtime provenance boundary

Volatile WebDriver BiDi publication-currentness and the separately qualified OriginWeave runtime revision are owned by #229 and docs/traceability/webdriver-bidi-publication-current.md. This issue does not maintain a second dated latest/previous publication snapshot or silently repin runtime compatibility. #316 consumes only the admitted capability and owns the protocol-specific evidence semantics needed to project Browser Session authority.

Current dependency authority — 23 September 2026 KST

The former 21 September authority named #229 3ec6326b... and a 634-ahead/25-behind relationship. Earlier history named #229 ce5074f..., #317 54d7367..., and a 164-ahead/7-behind relationship. Those values are historical only and no longer define dependency authority.

Required order is owner-first and acyclic: #212 central dependency/trusted-runtime/admission prerequisites → #229 current executable native CI/CodeQL/current-review/ruleset acceptance, with exact SAST/Security already GREEN → #317 ordinary non-force parent adoption preserving all valid deltas and current standards authority → #318/#321 ordered restack and parent-blob verification → #316 ACL/protocol proof integration → pinned-Chromium post-condition/destruction evidence under #292/#299. Do not patch parent-owned source or volatile standards metadata directly into #316.

Test-first acceptance

  • RED: retain an authority token, advance the same context/navigation epoch, and prove the old token cannot be converted into a BiDi presentation witness or command plan.
  • RED: destroy the context, record transport loss/recovery, or end the session and prove no adapter witness can be derived from stale authority.
  • RED: authority from another aggregate with reused external session/context/epoch values but distinct incarnation/isolation must fail before any adapter command or transport path.
  • RED: a consumed navigation/recovery witness cannot be replayed to mint a second presentation opportunity.
  • GREEN: a current authority validated by the owning aggregate can be projected through one narrow ACL into the exact browsing-context-bound BiDi presentation witness and plan only the admitted viewport/DPR/timezone capability. Screen-area ownership remains separate and must not imply complete Screen admission.
  • GREEN proof boundary: command planning/ACK remains distinct from independently observed browser post-condition and from cleanup/destruction proof.
  • Keep Browser Session independent of WebDriver BiDi/CDP/MCP. The adapter may depend outward on a narrow Browser Session proof contract; Browser Session must not depend on adapter protocol types.
  • Owned production rustdoc, tests, edge cases, and function/line/region/branch coverage remain 100%.

Real Chromium transport, presentation observation, interaction outcome, restoration/destruction, and cleanup remain acceptance under #292/#299 after #212 supplies the protected workflow/sandbox contract. No self-approval, force push, destructive rebase, workflow/ruleset/secret mutation, runtime repin, gate weakening, tag, release, or publication is authorized here.

Activity

  1. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Writer lease ACTIVE — source scope is a new stacked successor from #313 exact 6486e916dceb4ab5f33f7b390cd76fd4673d6007 only. Do not mutate #313/#229 source or PR state. Sequence: hostile stale-authority RED → minimum Browser Session lifetime-bound current-authority proof → originweave-bidi ACL bridge → exact-head GREEN. No transport implementation, workflow/ruleset/secret change, public witness constructor, force update/rebase, self-approval, merge, sandbox weakening, provider/model pin, tag, or release.

  2. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Additional ACL invariant from the live types: originweave-core::BrowsingContextId is a domain u64 identity, while originweave-bidi::WebDriverBidiBrowsingContext is the remote end's validated opaque string. The bridge must not stringify/coerce the domain id or accept an unrelated remote string from the caller. The exact BiDi browsing-context address must originate from the same reviewed lifecycle adapter mapping that produced the DisposableIsolationId/DisposableContextHandle, and the lifetime-bound current-authority proof must bind that mapping before command planning. Otherwise the ACL could be current in the domain aggregate yet target a different remote context.

  3. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Writer lease RELEASED — no source branch or PR was created. #314 remains the next ACL/buyer-gap contract, but #313's newly verified partial-creation cleanup uncertainty is a Browser Session foundation prerequisite and must be repaired first. The exact prerequisite remains 6486e916dceb4ab5f33f7b390cd76fd4673d6007 until a normal successor/integration changes it.

  4. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Prerequisite refinement from #315 exact 98a28db0ac95972419906f229badf35c4f5fa0d6: do not open the Browser Session→BiDi witness projection until the recovery-evidence gap in review 5164398667 is repaired and normally inherited into #313. RecoveryRequired is necessary but not sufficient if an uncertain partial create or duplicate adapter output discards the exact DisposableIsolationId/returned handle needed to reconcile remote state. The ACL must consume only current, normally owned authority; it must not create a workaround that reconstructs missing recovery identity from raw browser session/context ids. #315 also still has the separate exact-head repository-contract RED (DisposableContextDestroyError / cleanup unproven wording mismatch), so no predecessor GREEN transfers.

  5. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Prerequisite refinement from #315 review 5165103727: do not open the Browser Session→BiDi ACL while record_transport_loss() drops a first real transport-loss event merely because ownership is already RecoveryRequired. The ACL must not derive a current presentation witness or reconciliation command from a proof whose aggregate has unresolved ownership and a subsequently lost browser transport. #312/#315 must first preserve ownership-recovery and transport-liveness as distinct facts (or an explicit combined state/evidence), with a hostile RecoveryRequired → transport loss RED and fresh exact-head GREEN. Keep the lossless recovery identity required by review 5164398667; do not overwrite it by collapsing the state to plain TransportLost.

  6. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    ACL prerequisite refinement from #315 review 5165358933: the future Browser Session→BiDi projection must reject stale authority across sequential aggregate reincarnation, not just epoch changes inside one aggregate or concurrently distinct isolation ids. If A is destroyed/ended and B later reproduces the same external session id, remote user-context/isolation string, browsing-context id and local epoch, A's retained token must still be non-current and must not project to a BiDi witness. #312/#315 therefore need a non-reusable lifecycle/browser-generation proof carried through the authority and the reviewed remote-context/isolation mapping before #314 opens a consuming path. Do not treat the WebDriver BiDi user-context string alone as a durable generation capability, and do not reconstruct freshness from raw ids.

  7. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Prerequisite status update: #315 exact 0c6ed89c09ad16b5e170fd80604c29b16ce4f212 is repository GREEN in CI 34475535820, including exact production function/line/region/branch enforcement and Rust contracts/tests/Clippy/rustdoc. The Browser Session child now carries lossless recovery evidence, orthogonal transport-loss fact, incarnation/ABA protection through lifecycle I/O, destroy-failure quarantine, and fail-closed epoch overflow. It remains Draft solely because current-head qualifying independent review has not yet been obtained; current-head CodeRabbit review was requested.

    Do not open the ACL implementation by copying these mutable child internals. First require normal #315 adoption into #313 and fresh GREEN on the resulting #313 exact head. Then #314 may consume the Browser Session authority through the intended dependency direction and prove live revalidation immediately before deriving the private BiDi presentation witness. Raw IDs or retained authority tokens remain insufficient.

  8. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Writer lease ACTIVE — foundation prerequisite is now normally inherited into #229 exact 6d87dff5dc572fbd74d06309d574a998f23cf02f: #315 was ordinary-merged into #313, #313 exact bab489ab244e0edfdb309692ee1f9ecd2e7adde0 produced fresh CI GREEN, its resolved lifecycle thread was verified on parent source, and #313 was ordinary-merged into #229. This lease owns only a new stacked #314 successor from current #229; do not mutate #229/main or canonical workflow/sandbox/model-owner source. Sequence: inspect exact lifecycle↔remote-context mapping → hostile stale/mismatched-address RED → minimum lifetime-bound ACL proof → exact-head GREEN. No raw-id coercion, public witness constructor, force/destructive restack, self-approval, bypass, sandbox weakening, provider/model pin, tag or release.

  9. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Read-only reviewer handoff for #316 exact b1c1648127defb89723606207033f5da5826c3ca; active #314 source writer remains authoritative and I did not mutate its branch.

    Current hosted CI 34489022703 is terminal RED. Rust contracts 102911146862 fails the documentation fitness contract because ADR 0115 is not yet present in both canonical ADR/documentation indexes. Production coverage 102911147207 completes measurement and uploads artifact 10157093093 (sha256:b6708e9c9f5c8368a761b48c2a69a8aced246e0556d7f2e98ee6bc7b39a36494) but exact enforcement fails at lines=5804/5807, regions=7107/7108. Predecessor GREEN therefore does not transfer.

    More importantly, exact-head source still has a recovery-boundary defect. WebDriverBidiLifecycleAdapter::create_disposable_context receives a complete WebDriverBidiCreatedContext, but duplicate-remote rejection reduces it to CreateFailedUncertain(Some(isolation)), losing known domain browsing-context and opaque BiDi remote-context identity. Also, the adapter commits a normal binding before Browser Session can reject isolation-only or domain-context-only aliasing. That can leave bindings containing a protocol target for a handle Browser Session never adopted, while the complete tuple needed for safe reconciliation is lost. This is already acknowledged in ADR 0115 as an open follow-up, but because ambiguous cleanup must never guess ownership it should be closed before #316 adoption.

    I left COMMENT review 5168460322 with required hostile REDs: isolation-only alias, domain-context-only alias, and duplicate-remote alias must preserve the complete known created tuple in an adapter-local non-authorizing quarantine/recovery store distinct from accepted bindings; authorization must never consult quarantine and ambiguous tuples must not be auto-destroyed. Keep BiDi protocol strings out of Browser Session domain types. Then repair both canonical ADR indexes and restore fresh exact-head function/line/region/branch 100% plus repository contracts before ordinary adoption.

  10. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Additional exact-head blocker from #316 review 5168479840: the ACL currently protects presentation-plan projection but not the lifecycle port itself. WebDriverBidiLifecycleAdapter publicly implements DisposableContextPort, whose create/destroy methods accept raw BrowserSessionId + public BrowserSessionIncarnation (+ DisposableContextHandle for destroy). Downstream code with &mut adapter can therefore bypass the Browser Session aggregate: direct create can allocate untracked browser state; direct destroy can remove a mapped remote boundary while Browser Session still believes the context is Active. A retained PresentationMutationAuthority exposes enough identity to reconstruct the destroy key, and DisposableContextHandle::new is public.

    Before real BiDi lifecycle backend wiring, require a hostile compile/runtime contract proving downstream code cannot cause remote create/destroy without a fresh non-constructible Browser Session-issued lifecycle request/capability. Adapter should consume that opaque request; raw ids/equality/docs/module convention are insufficient. Keep Browser Session as lifecycle authority and BiDi as adapter.

  11. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Exact-head reviewer refinement for #316 b1c1648127defb89723606207033f5da5826c3ca: review 5168832953 found that adapter-local alias checks cannot by themselves close the rejected-create recovery gap because one BrowserSession may call create_disposable_context with different DisposableContextPort instances on successive calls. Adapter A can own (U,C1,R1) while fresh adapter B has no local knowledge and successfully creates/inserts (U,C2,R2) or (U2,C1,R2); only after B has committed its normal binding does the Browser Session aggregate reject the duplicate and enter RecoveryRequired.

    Required hostile RED: same Browser Session, two distinct lifecycle adapters; adopt via A, then force isolation-only and domain-context-only aliases via B. The B result must never become an authorizing normal binding, and the complete protocol tuple must remain only as non-authorizing recovery evidence.

    This means the fix needs an aggregate↔adapter transaction boundary rather than another local map scan. Prefer a pending create candidate plus Browser Session-issued non-constructible accept/reject completion: adapter keeps protocol identity private/pending, aggregate validates the domain handle, only accepted completion promotes to normal binding, rejected completion quarantines it. Combine this with the non-forgeable lifecycle attempt/destroy capability required by review 5168479840; raw IDs must not be sufficient for attempt, commit, or destroy. Do not move BiDi remote strings into the Browser Session domain.

  12. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Read-only handoff while source lease 5618765115 remains ACTIVE; I did not mutate feat/browser-session-bidi-acl or PR state. #316 is still exact b1c1648127defb89723606207033f5da5826c3ca, Ready, and hosted CI 34489022703 remains terminal RED.

    New review 5169424548 makes the lifecycle-port side door concrete as a presentation-target redirect: after Browser Session legitimately adopts (S,I,U,C)->R1 through adapter A, ordinary downstream code can seed a separate adapter B through the public DisposableContextPort using the same visible (S,I,U,C) but remote R2; B can then revalidate the real current authority against Browser Session and resolve its own exact-key map to R2. This defeats the ACL even without forging PresentationMutationAuthority.

    Please fold this into the existing side-door/cross-adapter repair: non-constructible lifecycle attempt/accept/destroy requests must also be bound to the same aggregate-approved lifecycle-port/adapter ownership identity, so an acceptance/capability cannot be replayed across arbitrary adapter instances. Required hostile RED is A-normal-adoption → B-direct-port seed with same lifecycle tuple/different remote → B authorization must fail before R2 is projected. Keep the remote string adapter-local and preserve rejected tuples only as non-authorizing quarantine evidence.

  13. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Read-only handoff while source lease 5618765115 remains ACTIVE; I did not mutate feat/browser-session-bidi-acl or PR state. #316 remains exact b1c1648127defb89723606207033f5da5826c3ca; hosted CI 34489022703 is still terminal RED.

    New review 5170088843 found a separate DDD/API-boundary defect: lifecycle_acl.rs currently introduces parallel WebDriverBidiPresentationOperation / AuthorizedWebDriverBidiPresentationAction / AuthorizedWebDriverBidiPresentationPlan semantics instead of safely connecting Browser Session authority to the canonical presentation_capabilities.rs contract (WebDriverBidiPresentationOwnership, WebDriverBidiPresentationCommand, plan_standard_presentation_commands, cleanup planner). #314 explicitly owns the missing safe consuming path for that private witness, so leaving two command vocabularies would preserve the original disconnected path and create transport/schema drift.

    Please repair this together with the active lifecycle-port work: keep ownership mint non-public and lifetime-bound, but route the ACL through one canonical presentation command representation/planner. If cloneability/lifetime of the existing command type prevents that, repair the canonical ownership type boundary or wrap it without exposing a stale cloneable capability; do not duplicate SetViewport/SetTimezone/Reset* payload schemas. Add a contract that standard apply/reset operations have one canonical representation. Existing cross-adapter/side-door/quarantine findings remain prerequisites.

  14. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Read-only handoff while source lease 5618765115 remains the latest ACTIVE lease; I did not mutate feat/browser-session-bidi-acl or PR state. #316 remains exact b1c1648127defb89723606207033f5da5826c3ca, and CI 34489022703 is still terminal RED.

    New review 5170615905 tightens the canonical-command repair from 5170088843: do not solve the duplicate command vocabulary by minting WebDriverBidiPresentationOwnership and returning bare existing WebDriverBidiPresentationCommands. The canonical ownership witness and command are currently owned/Clone, and the planners clone the witness into returned commands. A command produced after a valid Browser Session check could therefore be retained while the ACL borrow ends, then submitted after epoch advance, destruction, transport loss, or session end unless the execution boundary performs a fresh revalidation.

    Acceptance: keep one canonical command payload vocabulary, but make mutation authority ephemeral. A retained canonical intent must not be executable after lifecycle change without fresh Browser Session + lifecycle-adapter revalidation immediately before remote I/O. Prefer a non-cloneable/lifetime-bound authorized execution wrapper or equivalent live borrow through transport submission; do not expose a public witness constructor or rely on caller discipline. Existing lifecycle-port side door, cross-adapter target redirect, pending/accepted/quarantine transaction, and complete recovery-tuple findings remain prerequisites.

  15. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Read-only/source-safe handoff from #316 exact b1c1648127defb89723606207033f5da5826c3ca: new review 5171179154 adds a remote-liveness prerequisite that the current lifetime-bound ACL does not cover. The &BrowserSession / &adapter borrow prevents local Rust lifecycle mutation, but it cannot freeze the external browser. W3C WebDriver BiDi 2026-09-09 defines browsingContext.contextDestroyed, session cleanup closes the WebSocket, and empty non-default user contexts may be removed by the implementation. Therefore an authorized plan can remain type-valid while its remote context/session has already disappeared.

    Acceptance for the eventual transport boundary: subscribe/reconcile remote lifecycle events so contextDestroyed or session loss becomes adapter evidence and updates Browser Session recovery/transport-liveness before further mutation; immediately before browser I/O revalidate both current domain authority and adapter-observed remote membership. Do not silently recreate/rebind a destroyed remote target or use borrow lifetime/command ACK as lifecycle proof. Keep protocol event identities inside the BiDi ACL. Existing non-forgeable lifecycle request, adapter-ownership, pending/accepted/quarantine, canonical-command, and stale-intent findings remain prerequisites.

    I repaired the current PR-state mismatch by converting #316 to Draft because exact-head CI is still RED and unresolved security findings remain. No source branch, workflow, ruleset, sandbox, secret, provider/model, merge, tag, or release mutation was made.

  16. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Writer lease succession: prior lease 5618765115 has had no RELEASE, newer source-owner declaration, or source-head movement since 2026-09-10 12:35:48Z; feat/browser-session-bidi-acl remains exact b1c1648127defb89723606207033f5da5826c3ca after repeated fresh reads through 19:06Z. To avoid a stale single-writer lease deadlocking the hourly repair loop, this same OriginWeave writer now resumes ownership of #316 source from that exact head. Scope remains only feat/browser-session-bidi-acl; #229/main and canonical workflow/sandbox/model-owner source stay read-only. I will adopt any intervening commit by fresh-head check before each write, never force-update/rebase.

  17. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    Foundation prerequisite update from #317 exact 97e0a4d875166ad733e78c1d3f213454ee615f01: review 5171463467 found that the proposed lifecycle-port binding is still forgeable across adapter instances. DisposableContextPortId::new(u64) is public and the port self-reports its id, so distinct adapters A and B can both claim the same scalar id. The Browser Session then cannot distinguish B from the bound adapter, and a borrowed aggregate-issued lifecycle request can be relayed/replayed into B despite B never being the approved port.

    Do not restack/adopt #316 onto #317 until #317 adds a same-id/different-adapter hostile RED and closes it with a non-caller-constructible Browser Session-approved/linear port binding (or equivalent non-replayable ownership proof), then obtains fresh exact-head GREEN and independent review. Documentation that ids are distinct, randomness, or another caller-constructible scalar is insufficient. #316 continues to own protocol-specific pending→accepted/quarantined BiDi transaction and complete remote recovery tuple; do not move remote BiDi ids into Browser Session.

  18. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    #317 prerequisite update: the same-id/different-adapter case is now an executable exact-head RED, not only review reasoning. On #317 exact 9caf9bbe4228c443b7d5a4279831765a6a38765a, CI 34522121442 reaches the new hostile fixture after the stale Browser Session test implementations were repaired. Distinct adapter B self-reporting the already-bound id 101 is accepted for both create and destroy: create returns a fresh authority and destroy returns Ok(()), where both must fail before I/O with LifecyclePortMismatch. Exact evidence is recorded on #317 comment 5624503478.

    #317 is back to Draft and remains RED. Do not adopt/restack #316 until this is closed with non-forgeable/non-replayable aggregate-approved adapter ownership and fresh exact-head repository GREEN; keep #316's protocol-specific pending/accepted/quarantine and complete BiDi recovery tuple separate.

  19. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    #317 prerequisite has one more owner-boundary blocker before #316 may restack. Exact 9caf9bbe4228c443b7d5a4279831765a6a38765a, review 5171724702: Browser Session currently calls the public trait callback DisposableContextPort::port_id(&self) as preflight before aggregate lifecycle authority is issued/validated. &self is not a purity boundary; an implementation can perform browser/network side effects through interior mutability. Thus a documented side-effect-free port_id() cannot prove reject-before-I/O.

    Keep #316 Draft and do not restack onto #317 until #317 removes arbitrary pre-authority adapter callbacks, preserves the same-id/different-adapter hostile RED, and obtains fresh exact-head GREEN. A session-approved composition/binding capability or session-owned/linear port wrapper is acceptable if adapter execution occurs only under an already validated aggregate request. #316 still owns protocol-specific pending→accepted/quarantined tuples, remote-liveness reconciliation, canonical command intent, and complete BiDi recovery evidence; do not move those remote identities into Browser Session.

  20. seonghobae commented on Sep 10, 2026

    @seonghobae
    ContributorAuthor

    #317 prerequisite advanced to exact d43a4d86c8487ebdb9db9f1c4650fb7ee6225afc and is back in Draft. CI 34524654914 is terminal RED. Production coverage job 103030469480 proves review 5171724702: the new hostile test makes port_id(&self) increment interior state, and Browser Session calls it before lifecycle authority (1 observed, 0 required). Keep #316 Draft until #317 removes that pre-authority adapter callback and also closes the separate same-id/different-adapter replay RED with fresh exact-head GREEN. ADR 0114 stays Browser Session-owned; ADR 0115 and BiDi pending/quarantine/recovery remain #316-owned.

  21. seonghobae commented on Sep 11, 2026

    @seonghobae
    ContributorAuthor

    Fresh standards correction for the ACL owner path: W3C's canonical latest-published WebDriver BiDi TR currently resolves to 24 August 2026 (WD-webdriver-bidi-20260824), not the 9-September publication named in this issue body. Preserve the separately owned runtime-qualified compatibility pin until requalification; this correction is about authoritative standards provenance only. #317 has already aligned ADR/traceability/repository-contract references to the verified 24-Aug publication. #316 should inherit that provenance when it non-force restacks onto the verified Browser Session successor.

  22. seonghobae commented on Sep 11, 2026

    @seonghobae
    ContributorAuthor

    #317 review 5181698838과 #316 exact-head review 5181721957로 ACL invariant에 직접 걸리는 public-surface 결함을 확인했습니다. #316 authorize_standard_presentation은 public BrowserSession::presentation_authority(raw BrowsingContextId)로 retained token을 재검증합니다. 그런데 BoundBrowserSession::browser_session()이 policy/ACL용 read-only &BrowserSession을 그대로 노출하므로 caller가 같은 raw context id로 현재 token을 직접 발급한 뒤 ACL 비교를 통과할 수 있습니다. 현재 #314의 “proof must be non-caller-constructible” 요구와 모순입니다.

    #317에서 read model과 capability issuance를 type surface로 분리한 verified successor를 먼저 만들고, #316은 그 후 non-force restack하여 point-of-use fresh-validation guard/borrow를 소비해야 합니다. Retained PresentationMutationAuthority + public snapshot lookup 조합은 acceptance로 인정하지 마십시오.

  23. seonghobae commented on Sep 11, 2026

    @seonghobae
    ContributorAuthor

    Standards provenance 정정이 필요합니다. Fresh W3C 확인 기준 최신 published WebDriver BiDi TR은 24 August 2026 (WD-webdriver-bidi-20260824)이고, 9 September 2026은 w3c.github.io/webdriver-bidi/의 Editor's Draft입니다. 이 issue body의 “latest-published ... 9 September 2026” 문구는 #317 review 5183426050과 함께 수리 대상으로 보겠습니다. Runtime-qualified revision(현재 2026-09-03), latest published TR, current Editor's Draft를 서로 독립된 provenance 축으로 유지해야 합니다. ACL/lifecycle acceptance 자체는 Editor's Draft의 current semantics를 사용할 수 있으며, 이 정정은 publication status를 바로잡는 것입니다.

  24. seonghobae commented on Sep 11, 2026

    @seonghobae
    ContributorAuthor

    Standards-provenance correction for this issue body: latest published W3C WebDriver BiDi TR is the Working Draft dated 24 August 2026 (WD-webdriver-bidi-20260824). The 9 September 2026 document is the current Editor’s Draft. Runtime-qualified OriginWeave revision remains a third, separate compatibility axis. The issue body currently labels 9 September as latest-published and should not be used as publication-status evidence until that text is repaired. This does not change the fresh point-of-use validation invariant or #318 navigation-lifecycle RED semantics.

  25. seonghobae commented on Sep 22, 2026

    @seonghobae
    ContributorAuthor

    2026-09-22 current central-prerequisite authority

    This supersedes the stale .github#2291@a8d6261d... prerequisite paragraph in the issue body while preserving #314's Browser Session/BiDi ACL ownership and acceptance contract.

    Canonical .github#2291 is now exact 1794626af3473ef23b9c2e678c3f06fd6c11636f, Ready / mergeable. Its former 24-site specialized-fixture trusted-runtime RED is source-repaired in the canonical owner; current hosted evidence is partial rather than accepted: Runtime Quality 35661200424 and SAST 35672611347 succeeded, while Security 35672611396, Python Security 35672611349, and CodeQL 35672611353 remain nonterminal with remaining jobs queued. .github#2278@8a5251bf... remains the independent AnyIO 4.14.2 owner prerequisite.

    OriginWeave #229 exact 3ec6326... has Security/SAST success, native CI skipped, and CodeQL failure at the central current-head verdict-publication/wake boundary (VERDICT_STATE=pending after successful dispatch), so #229 is not accepted. #317 remains exact 70cc9d8..., 634 ahead / 25 behind / diverged from current #229. Required order is unchanged: central owner acceptance → #229 executable native CI + resolved CodeQL verdict + review/ruleset acceptance → ordinary/non-force #229→#317 reconciliation preserving all valid child deltas → #318/#321 → #316 ACL/protocol proof. No leaf duplication, wake commit, or predecessor evidence transfer is justified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions