You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OriginWeave's governed-browser source and repository contracts now require real pinned Chromium execution with sandboxing enabled, but the current repository-local workflow authority is inconsistent with that contract and product PRs are not authorized to repair .github/** themselves.
OriginWeave Refresh governance audit after clearfolio rollout #43 exact head: e5db34c57d7b1de61d613a196117ca2cce296bec, Draft, reconstructed non-destructively so its .github/workflows/mv3-compatibility.yml is byte-for-byte protected-main rather than a leaf-owned workflow mutation.
tests/test_mv3_compatibility_contract.py::test_workflow_installs_chromium_sandbox_helper requires the pinned Chrome for Testing helper to be root-owned, mode 4755, and exposed through CHROME_DEVEL_SANDBOX.
Protected-main/current-#43 .github/workflows/mv3-compatibility.yml downloads/extracts Chrome for Testing 150.0.7871.129 and chmods only chrome/chromedriver; it does not install/configure chrome_sandbox and does not export CHROME_DEVEL_SANDBOX.
The product runner intentionally no longer passes --no-sandbox.
Historical exact-head #43 evidence proved the pinned archive contains a usable chrome_sandbox and that root:root + mode 4755 + CHROME_DEVEL_SANDBOX completed repeated real Chromium MV3 passes. That predecessor execution is technical feasibility evidence only; it is not current-head GREEN or current workflow authorization.
Chromium's current Ubuntu developer-build guidance warns that --no-sandbox disables critical security features and should never be used for open-web browsing. Chromium's SUID sandbox guidance shows the raw-build helper shape (chown root:root, chmod 4755, CHROME_DEVEL_SANDBOX), while current Ubuntu 23.10+ guidance also permits a narrowly reviewed AppArmor/user-namespace configuration. Therefore the central design may use the setuid helper or a demonstrably equivalent sandbox-capable mechanism, but it must not weaken sandboxing.
Required central architecture
Create or extend a canonical reusable workflow in ContextualWisdomLab/.github for OriginWeave's pinned Chromium/MV3 evidence, with an exact-SHA thin caller in OriginWeave. Do not copy product-domain browser policy into .github; central ownership is limited to trusted workflow/toolchain/evidence mechanics.
The reusable workflow should own at minimum:
immutable Chrome for Testing / ChromeDriver identity and checksum verification;
a sandbox-capable Ubuntu execution setup that preserves Chromium sandboxing without --no-sandbox or global disabling of Ubuntu's user-namespace security;
least-privilege permissions, no provider/model credentials, bounded network behavior, deterministic artifact retention, and exact caller-head binding;
execution of OriginWeave-owned runner entry points rather than copying browser-domain logic into the central repository;
typed distinction between runner unavailable, browser startup/sandbox failure, product-contract failure, cancellation, and successful current-head evidence;
immutable action pins and workflow-contract tests protecting the helper/setup and caller SHA;
enough inputs to support the existing downloads/compatibility Agent Task lane and the Repair fragile OpenCode approval reasons from evidence #245 Web Audio privacy evidence without creating independent workflow authorities for each product feature.
RED acceptance
On the current protected-main workflow shape, a deterministic contract must demonstrate that sandbox-preserving OriginWeave browser execution requires setup not supplied by the workflow. A queued/unassigned job is incomplete evidence and does not substitute for this source-level RED.
Also retain a fixture proving that --no-sandbox, empty/disabled sandbox configuration, missing helper/AppArmor allowance, wrong Chrome/ChromeDriver identity, or an unverified caller revision cannot become successful browser-security evidence.
GREEN acceptance
The central reusable workflow is protected-main integrated through normal review/check policy.
OriginWeave consumes it through a thin exact-SHA caller with no duplicated provider/model/browser-policy authority.
Repair fragile OpenCode approval reasons from evidence #245's Web Audio product delta is preserved and its evidence is integrated through the same governed workflow owner or a justified reusable sub-lane; its current leaf workflow mutation is not treated as permanent authority.
Repository contracts, current-head CI/coverage/rustdoc where applicable, SAST/Security, artifact/provenance evidence and live governance gates are terminal and exact-head bound.
Owner-path defect
OriginWeave's governed-browser source and repository contracts now require real pinned Chromium execution with sandboxing enabled, but the current repository-local workflow authority is inconsistent with that contract and product PRs are not authorized to repair
.github/**themselves.Fresh exact evidence:
main:c789b802fc98a8d7fd8c09d9327f36828054d2a1.e5db34c57d7b1de61d613a196117ca2cce296bec, Draft, reconstructed non-destructively so its.github/workflows/mv3-compatibility.ymlis byte-for-byte protected-main rather than a leaf-owned workflow mutation.tests/test_mv3_compatibility_contract.py::test_workflow_installs_chromium_sandbox_helperrequires the pinned Chrome for Testing helper to be root-owned, mode4755, and exposed throughCHROME_DEVEL_SANDBOX..github/workflows/mv3-compatibility.ymldownloads/extracts Chrome for Testing150.0.7871.129and chmods onlychrome/chromedriver; it does not install/configurechrome_sandboxand does not exportCHROME_DEVEL_SANDBOX.--no-sandbox.5100544074; ⚡ Bolt: [performance improvement] PR 리뷰 스케줄러 동기 호출 병목 개선 #705100592088; Repair fragile OpenCode approval reasons from evidence #2455100581535. OriginWeave issue Fix Strix protobuf dependency lock #212 is the leaf-side dependency ledger.33740544442, job100601170874, and ⚡ Bolt: [performance improvement] PR 리뷰 스케줄러 동기 호출 병목 개선 #70 MV3 run33738452556, job100594512852, remain queued withsteps=[],runner_id=0, no assigned runner/group. Runner acquisition is tracked separately by ops: diagnose and bound organization GitHub Actions queue starvation #712/Actions queue saturation: 120 open PRs + self-amplifying scheduler block all org merges (pg-erd-cloud: 0 merges since 2026-08-20) #1531; do not conflate capacity with the workflow-source defect.Historical exact-head #43 evidence proved the pinned archive contains a usable
chrome_sandboxand that root:root + mode 4755 +CHROME_DEVEL_SANDBOXcompleted repeated real Chromium MV3 passes. That predecessor execution is technical feasibility evidence only; it is not current-head GREEN or current workflow authorization.Chromium's current Ubuntu developer-build guidance warns that
--no-sandboxdisables critical security features and should never be used for open-web browsing. Chromium's SUID sandbox guidance shows the raw-build helper shape (chown root:root,chmod 4755,CHROME_DEVEL_SANDBOX), while current Ubuntu 23.10+ guidance also permits a narrowly reviewed AppArmor/user-namespace configuration. Therefore the central design may use the setuid helper or a demonstrably equivalent sandbox-capable mechanism, but it must not weaken sandboxing.Required central architecture
Create or extend a canonical reusable workflow in
ContextualWisdomLab/.githubfor OriginWeave's pinned Chromium/MV3 evidence, with an exact-SHA thin caller in OriginWeave. Do not copy product-domain browser policy into.github; central ownership is limited to trusted workflow/toolchain/evidence mechanics.The reusable workflow should own at minimum:
--no-sandboxor global disabling of Ubuntu's user-namespace security;RED acceptance
On the current protected-main workflow shape, a deterministic contract must demonstrate that sandbox-preserving OriginWeave browser execution requires setup not supplied by the workflow. A queued/unassigned job is incomplete evidence and does not substitute for this source-level RED.
Also retain a fixture proving that
--no-sandbox, empty/disabled sandbox configuration, missing helper/AppArmor allowance, wrong Chrome/ChromeDriver identity, or an unverified caller revision cannot become successful browser-security evidence.GREEN acceptance
Non-goals
--no-sandbox..github.Coordinate with
.github#712/.github#1531for runner/queue control and OriginWeave#212 for leaf adoption. Keep those causal classes separate.