Buyer-visible gap
originweave-fingerprint owns pure presentation identity. OriginWeave still needs browser-domain proof that an admitted profile is actually applied before page script, observed from the same version-qualified Chromium context, survives required failure cases, and is safely restored or destroyed. Protocol acknowledgement alone is not success. MCP/driver transports, LLMs and sibling owners must not become deterministic browser-policy or presentation-truth owners.
Current dependency authority — 23 September 2026 KST
Canonical presentation/WebDriver BiDi parent #229 is exact 60318092c410111924415b3e20ee3f4186e6472a, open / Draft / mergeable on protected main@87c4daa1830bac5a5228b6036752ad5633232085. W3C's live WebDriver BiDi publication history currently lists 16 September 2026, 14 September 2026, 9 September 2026, then 3 September 2026 Working Drafts. Publication freshness and runtime qualification remain separate authorities: OriginWeave's independently qualified adapter pin remains 3 September 2026 until dedicated schema/browser compatibility evidence proves a newer revision. Current #229 ordinary-forward repair lineage currentizes the publication receipt/ADR and removes prose-label coupling from the currentness oracle. Exact-head CI 35713817985 is Draft-skipped; SAST 35713817883 and Security 35713817945 are terminal SUCCESS. CodeQL 35713817902 remains nonterminal: Detect 106700519278 is SUCCESS, its three compatibility jobs executed and failed closed only because no authenticated terminal current-head verdict existed, and coordinator 106826100321 remains pre-step queued with runner_id=0 and steps=[]. Fresh #229 review inspection has 0 unresolved threads but no qualifying current-head APPROVED review. Predecessor GREEN/review evidence does not transfer.
Browser Session successor #317 is exact 70cc9d8ab9cbb79e3f7c8635ba5c4bec67d80b73, open / Draft / non-mergeable. Fresh GitHub compare from current #229 is ahead 634 / behind 31 / diverged at merge base 8dcacbaebf2a6f02c5bbda8e8d6cc8bce474b693. Reconciliation must be ordinary/non-force, preserve all 634 valid child deltas, and adopt/adapt current #229 standards truth without duplicating volatile publication metadata in Browser Session domain documents.
The downstream Browser Session chain remains #318 exact 983fa652180e47e479c99b8903755f1fd60f0746 → #321 exact 9d3c51e7ff66c952dba203a04704e53df78d2b0e → protocol/ACL owner #316 exact 8ca6c5a190d9ad2b4c7843d440e91f6070d681c2. These are Draft generations on predecessor ancestry. Mergeability on an individual child is topology only, not acceptance.
Issue #212 remains the canonical owner for the volatile central workflow/sandbox/admission chain. Canonical AnyIO owner .github#2278@8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5 carries the one-file AnyIO 4.14.0 → 4.14.2 repair; SAST, Python Security, and Security Scan are GREEN while CodeQL remains fail-closed on central verdict publication and current-head approval is missing. Canonical trusted Strix owner .github#2291@1794626af3473ef23b9c2e678c3f06fd6c11636f has Runtime Quality/SAST/Security GREEN, Python Security failing only at pip-audit while inheriting protected AnyIO 4.14.0, and nonterminal CodeQL. OriginWeave must not copy either owner repair or weaken browser sandboxing.
The former 21 September authority named #229 3ec6326b... and a 634-ahead/25-behind relationship. Earlier history named #229 c7b7b0d..., #317 5dc7592..., and 562-ahead/12-behind. Those values are historical only and no longer define dependency authority.
Browser acceptance invariants
originweave-fingerprint remains the pure profile/value owner; browser adapters depend inward on it.
- Capability claims are explicit per admitted browser/protocol revision; partial required surfaces fail closed.
- Apply occurs before the target page-script/navigation epoch; navigation/renderer replacement invalidates evidence until Browser Session re-establishes authority.
- ACK is not evidence. Read page-visible post-conditions from the exact owned context.
- Apply/cleanup authority is symmetric. Reusable contexts require exact predecessor restoration; otherwise prove destruction of a Browser Session-owned disposable context/profile.
BrowserSessionIncarnation participates in authorization validation and sequential-ABA separation.
- Unsupported revision/mode, partial application, command error, observed mismatch, renderer/process failure or cleanup ambiguity is non-passing.
- Presentation consistency is privacy/compatibility behavior, not authorization to bypass CAPTCHA, consent or access control.
Real Chromium lane
PR #299 remains the browser-observed acceptance lane. Native repository CI does not substitute for browser success. Its pinned Chrome/ChromeDriver 150.0.7871.129 generation is immutable historical reproducibility evidence and remains browser RED because session creation never reached the page-observed presentation/interaction/reset post-conditions.
Current-Stable Chromium qualification is a separate versioned evidence generation owned through #212 and the canonical central MV3 workflow. Do not rewrite the Chrome 150 receipt in place, infer a matching Chrome-for-Testing artifact without an immutable asset/digest receipt, copy the central reusable workflow, or use --no-sandbox.
A passing pinned-browser run requires all three trials to prove ambient-distinct baseline → presentation apply → page-observed target → browser-computed semantics → native clear/type/click → accepted outcome → URL stability → explicit presentation reset → page-observed original baseline → WebDriver session/profile cleanup.
Delivery order
Required order is owner-first and acyclic:
#212 central dependency/trusted-runtime/admission prerequisites reach causal GREEN and normal protected integration → current #229 executable native CI/CodeQL/current-review/ruleset acceptance on repaired standards authority, with exact SAST/Security already GREEN → ordinary/non-force #229→#317 reconciliation preserving current parent truth + all 634 valid child deltas → fresh #317 executable repository/security/whole-current-head and owned-quality closure → #318 → #321 → #316 ordered non-force restacks → canonical central MV3 workflow acceptance/immutable consumer pin → #299 replay with actual session creation and complete page-observed post-conditions.
Keep this issue open until the exact pinned-Chromium path proves the complete sequence and reaches protected main through normal review and required workflows. No self-approval, bypass, force push, destructive rebase, gate weakening, workflow copy, source-neutral wake commit, merge, tag, release or publication is authorized here.
Buyer-visible gap
originweave-fingerprintowns pure presentation identity. OriginWeave still needs browser-domain proof that an admitted profile is actually applied before page script, observed from the same version-qualified Chromium context, survives required failure cases, and is safely restored or destroyed. Protocol acknowledgement alone is not success. MCP/driver transports, LLMs and sibling owners must not become deterministic browser-policy or presentation-truth owners.Current dependency authority — 23 September 2026 KST
Canonical presentation/WebDriver BiDi parent #229 is exact
60318092c410111924415b3e20ee3f4186e6472a, open / Draft / mergeable on protectedmain@87c4daa1830bac5a5228b6036752ad5633232085. W3C's live WebDriver BiDi publication history currently lists 16 September 2026, 14 September 2026, 9 September 2026, then 3 September 2026 Working Drafts. Publication freshness and runtime qualification remain separate authorities: OriginWeave's independently qualified adapter pin remains 3 September 2026 until dedicated schema/browser compatibility evidence proves a newer revision. Current #229 ordinary-forward repair lineage currentizes the publication receipt/ADR and removes prose-label coupling from the currentness oracle. Exact-head CI35713817985is Draft-skipped; SAST35713817883and Security35713817945are terminal SUCCESS. CodeQL35713817902remains nonterminal: Detect106700519278is SUCCESS, its three compatibility jobs executed and failed closed only because no authenticated terminal current-head verdict existed, and coordinator106826100321remains pre-step queued withrunner_id=0andsteps=[]. Fresh #229 review inspection has 0 unresolved threads but no qualifying current-headAPPROVEDreview. Predecessor GREEN/review evidence does not transfer.Browser Session successor #317 is exact
70cc9d8ab9cbb79e3f7c8635ba5c4bec67d80b73, open / Draft / non-mergeable. Fresh GitHub compare from current #229 is ahead 634 / behind 31 / diverged at merge base8dcacbaebf2a6f02c5bbda8e8d6cc8bce474b693. Reconciliation must be ordinary/non-force, preserve all 634 valid child deltas, and adopt/adapt current #229 standards truth without duplicating volatile publication metadata in Browser Session domain documents.The downstream Browser Session chain remains #318 exact
983fa652180e47e479c99b8903755f1fd60f0746→ #321 exact9d3c51e7ff66c952dba203a04704e53df78d2b0e→ protocol/ACL owner #316 exact8ca6c5a190d9ad2b4c7843d440e91f6070d681c2. These are Draft generations on predecessor ancestry. Mergeability on an individual child is topology only, not acceptance.Issue #212 remains the canonical owner for the volatile central workflow/sandbox/admission chain. Canonical AnyIO owner
.github#2278@8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5carries the one-file AnyIO4.14.0 → 4.14.2repair; SAST, Python Security, and Security Scan are GREEN while CodeQL remains fail-closed on central verdict publication and current-head approval is missing. Canonical trusted Strix owner.github#2291@1794626af3473ef23b9c2e678c3f06fd6c11636fhas Runtime Quality/SAST/Security GREEN, Python Security failing only atpip-auditwhile inheriting protected AnyIO 4.14.0, and nonterminal CodeQL. OriginWeave must not copy either owner repair or weaken browser sandboxing.The former 21 September authority named #229
3ec6326b...and a 634-ahead/25-behind relationship. Earlier history named #229c7b7b0d..., #3175dc7592..., and 562-ahead/12-behind. Those values are historical only and no longer define dependency authority.Browser acceptance invariants
originweave-fingerprintremains the pure profile/value owner; browser adapters depend inward on it.BrowserSessionIncarnationparticipates in authorization validation and sequential-ABA separation.Real Chromium lane
PR #299 remains the browser-observed acceptance lane. Native repository CI does not substitute for browser success. Its pinned Chrome/ChromeDriver
150.0.7871.129generation is immutable historical reproducibility evidence and remains browser RED because session creation never reached the page-observed presentation/interaction/reset post-conditions.Current-Stable Chromium qualification is a separate versioned evidence generation owned through #212 and the canonical central MV3 workflow. Do not rewrite the Chrome 150 receipt in place, infer a matching Chrome-for-Testing artifact without an immutable asset/digest receipt, copy the central reusable workflow, or use
--no-sandbox.A passing pinned-browser run requires all three trials to prove ambient-distinct baseline → presentation apply → page-observed target → browser-computed semantics → native clear/type/click → accepted outcome → URL stability → explicit presentation reset → page-observed original baseline → WebDriver session/profile cleanup.
Delivery order
Required order is owner-first and acyclic:
#212 central dependency/trusted-runtime/admission prerequisites reach causal GREEN and normal protected integration → current #229 executable native CI/CodeQL/current-review/ruleset acceptance on repaired standards authority, with exact SAST/Security already GREEN → ordinary/non-force #229→#317 reconciliation preserving current parent truth + all 634 valid child deltas → fresh #317 executable repository/security/whole-current-head and owned-quality closure → #318 → #321 → #316 ordered non-force restacks → canonical central MV3 workflow acceptance/immutable consumer pin → #299 replay with actual session creation and complete page-observed post-conditions.
Keep this issue open until the exact pinned-Chromium path proves the complete sequence and reaches protected main through normal review and required workflows. No self-approval, bypass, force push, destructive rebase, gate weakening, workflow copy, source-neutral wake commit, merge, tag, release or publication is authorized here.