You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Browser Session foundation introduced a non-caller-mintable lifecycle authority, but the product still needs a safe ACL from current live aggregate authority into the version-qualified originweave-bidi presentation planner. A public constructor or conversion from a retained PresentationMutationAuthority snapshot would reopen the authority gap: authority retained across epoch advance, navigation invalidation, destruction, transport loss, recovery, or session end could be planned after it became stale.
Historical #313 was merged into the #229 branch lineage; it is not the current Browser Session authority surface. The active deterministic Browser Session foundation is #317, and the active protocol-specific ACL/proof implementation lane is #316. Keep this issue open until that current lineage reaches executable exact-head acceptance and protected integration.
Browser Session remains lifecycle/policy authority; WebDriver BiDi remains an adapter. This issue does not own browser transport/sandbox mechanics, Keyverse, EgressWeave, contextual-orchestrator, Wardnet, download persistence, or real-browser release acceptance.
Required invariant
A BiDi presentation witness may be produced only from authority that the live BrowserSession aggregate has revalidated as current at the point of adapter use. The validation proof must be non-caller-constructible and bound to the owning aggregate/incarnation/context generation so stale or foreign authority cannot reach command planning or port I/O.
Raw BrowserSessionId, BrowsingContextId, DisposableIsolationId, protocol navigation id, or a retained PresentationMutationAuthority alone is insufficient. Command acknowledgement is not proof that presentation state was applied, restored, or destroyed.
Standards/runtime provenance boundary
Volatile WebDriver BiDi publication-currentness and the separately qualified OriginWeave runtime revision are owned by #229 and docs/traceability/webdriver-bidi-publication-current.md. This issue does not maintain a second dated latest/previous publication snapshot or silently repin runtime compatibility. #316 consumes only the admitted capability and owns the protocol-specific evidence semantics needed to project Browser Session authority.
Current dependency authority — 23 September 2026 KST
feat: add privacy-preserving presentation identity kernel #229 exact 60318092c410111924415b3e20ee3f4186e6472a — canonical standards/capability parent, open / Draft / mergeable. W3C's live publication history lists 16 September 2026, 14 September 2026, 9 September 2026, then 3 September 2026 Working Drafts. The independently runtime-qualified OriginWeave adapter pin remains 3 September 2026. Current repair lineage updates the canonical receipt/ADR and removes human Markdown-label coupling from the test oracle. Exact CI 35713817985 is Draft-skipped; SAST 35713817883 and Security 35713817945 are terminal SUCCESS. CodeQL 35713817902 remains nonterminal: Detect 106700519278 is SUCCESS, Actions/Python/JavaScript compatibility jobs executed and failed closed only because the authenticated terminal current-head verdict was absent, and coordinator 106826100321 remains pre-step queued with runner_id=0 and steps=[]. Fresh review inspection shows 0 unresolved threads and no qualifying current-head APPROVED review. No predecessor review/check evidence transfers.
feat(bidi): bind current Browser Session authority to BiDi planning #316 exact 8ca6c5a190d9ad2b4c7843d440e91f6070d681c2 — canonical protocol owner for pending/accepted/quarantined tuple truth, event correlation/replay, remote-liveness interpretation, ACL projection, and proof qualification. It remains Draft; mergeability is topology, not acceptance.
[Governance] Repair MV3 workflow ownership and sandbox contract #212 owns the volatile central workflow/sandbox/admission chain. Canonical .github#2278@8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5 owns the AnyIO 4.14.0 → 4.14.2 dependency repair and is GREEN on SAST/Python Security/Security while CodeQL remains fail-closed on central verdict publication and current-head approval is missing. Canonical .github#2291@1794626af3473ef23b9c2e678c3f06fd6c11636f is GREEN on Runtime Quality/SAST/Security, fails Python Security only at pip-audit while inheriting protected AnyIO 4.14.0, and has nonterminal CodeQL. Neither owner delta may be copied into this Browser Session/BiDi lane.
The former 21 September authority named #2293ec6326b... and a 634-ahead/25-behind relationship. Earlier history named #229ce5074f..., #31754d7367..., and a 164-ahead/7-behind relationship. Those values are historical only and no longer define dependency authority.
Required order is owner-first and acyclic: #212 central dependency/trusted-runtime/admission prerequisites → #229 current executable native CI/CodeQL/current-review/ruleset acceptance, with exact SAST/Security already GREEN → #317 ordinary non-force parent adoption preserving all valid deltas and current standards authority → #318/#321 ordered restack and parent-blob verification → #316 ACL/protocol proof integration → pinned-Chromium post-condition/destruction evidence under #292/#299. Do not patch parent-owned source or volatile standards metadata directly into #316.
Test-first acceptance
RED: retain an authority token, advance the same context/navigation epoch, and prove the old token cannot be converted into a BiDi presentation witness or command plan.
RED: destroy the context, record transport loss/recovery, or end the session and prove no adapter witness can be derived from stale authority.
RED: authority from another aggregate with reused external session/context/epoch values but distinct incarnation/isolation must fail before any adapter command or transport path.
RED: a consumed navigation/recovery witness cannot be replayed to mint a second presentation opportunity.
GREEN: a current authority validated by the owning aggregate can be projected through one narrow ACL into the exact browsing-context-bound BiDi presentation witness and plan only the admitted viewport/DPR/timezone capability. Screen-area ownership remains separate and must not imply complete Screen admission.
GREEN proof boundary: command planning/ACK remains distinct from independently observed browser post-condition and from cleanup/destruction proof.
Keep Browser Session independent of WebDriver BiDi/CDP/MCP. The adapter may depend outward on a narrow Browser Session proof contract; Browser Session must not depend on adapter protocol types.
Owned production rustdoc, tests, edge cases, and function/line/region/branch coverage remain 100%.
Real Chromium transport, presentation observation, interaction outcome, restoration/destruction, and cleanup remain acceptance under #292/#299 after #212 supplies the protected workflow/sandbox contract. No self-approval, force push, destructive rebase, workflow/ruleset/secret mutation, runtime repin, gate weakening, tag, release, or publication is authorized here.
Gap and current owner
The Browser Session foundation introduced a non-caller-mintable lifecycle authority, but the product still needs a safe ACL from current live aggregate authority into the version-qualified
originweave-bidipresentation planner. A public constructor or conversion from a retainedPresentationMutationAuthoritysnapshot would reopen the authority gap: authority retained across epoch advance, navigation invalidation, destruction, transport loss, recovery, or session end could be planned after it became stale.Historical #313 was merged into the #229 branch lineage; it is not the current Browser Session authority surface. The active deterministic Browser Session foundation is #317, and the active protocol-specific ACL/proof implementation lane is #316. Keep this issue open until that current lineage reaches executable exact-head acceptance and protected integration.
Browser Session remains lifecycle/policy authority; WebDriver BiDi remains an adapter. This issue does not own browser transport/sandbox mechanics, Keyverse, EgressWeave, contextual-orchestrator, Wardnet, download persistence, or real-browser release acceptance.
Required invariant
A BiDi presentation witness may be produced only from authority that the live
BrowserSessionaggregate has revalidated as current at the point of adapter use. The validation proof must be non-caller-constructible and bound to the owning aggregate/incarnation/context generation so stale or foreign authority cannot reach command planning or port I/O.Raw
BrowserSessionId,BrowsingContextId,DisposableIsolationId, protocol navigation id, or a retainedPresentationMutationAuthorityalone is insufficient. Command acknowledgement is not proof that presentation state was applied, restored, or destroyed.Standards/runtime provenance boundary
Volatile WebDriver BiDi publication-currentness and the separately qualified OriginWeave runtime revision are owned by #229 and
docs/traceability/webdriver-bidi-publication-current.md. This issue does not maintain a second dated latest/previous publication snapshot or silently repin runtime compatibility. #316 consumes only the admitted capability and owns the protocol-specific evidence semantics needed to project Browser Session authority.Current dependency authority — 23 September 2026 KST
60318092c410111924415b3e20ee3f4186e6472a— canonical standards/capability parent, open / Draft / mergeable. W3C's live publication history lists 16 September 2026, 14 September 2026, 9 September 2026, then 3 September 2026 Working Drafts. The independently runtime-qualified OriginWeave adapter pin remains 3 September 2026. Current repair lineage updates the canonical receipt/ADR and removes human Markdown-label coupling from the test oracle. Exact CI35713817985is Draft-skipped; SAST35713817883and Security35713817945are terminal SUCCESS. CodeQL35713817902remains nonterminal: Detect106700519278is SUCCESS, Actions/Python/JavaScript compatibility jobs executed and failed closed only because the authenticated terminal current-head verdict was absent, and coordinator106826100321remains pre-step queued withrunner_id=0andsteps=[]. Fresh review inspection shows 0 unresolved threads and no qualifying current-headAPPROVEDreview. No predecessor review/check evidence transfers.70cc9d8ab9cbb79e3f7c8635ba5c4bec67d80b73— Browser Session lifecycle/recovery/navigation authority, open / Draft / non-mergeable. Fresh compare from current feat: add privacy-preserving presentation identity kernel #229 is ahead 634 / behind 31 / diverged at merge base8dcacbaebf2a6f02c5bbda8e8d6cc8bce474b693. Reconciliation must preserve all 634 valid child deltas and ordinary/non-force adopt/adapt current feat: add privacy-preserving presentation identity kernel #229 standards authority while keeping Browser Session's stronger single-writer provenance contract.983fa652180e47e479c99b8903755f1fd60f0746— navigation-acceptance child on predecessor fix(browser-session): require aggregate-issued lifecycle request authority #317 ancestry.9d3c51e7ff66c952dba203a04704e53df78d2b0e— sibling-recreation/ABA child of test(browser-session): invalidate stale authority on observed navigation #318.8ca6c5a190d9ad2b4c7843d440e91f6070d681c2— canonical protocol owner for pending/accepted/quarantined tuple truth, event correlation/replay, remote-liveness interpretation, ACL projection, and proof qualification. It remains Draft; mergeability is topology, not acceptance..github#2278@8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5owns the AnyIO4.14.0 → 4.14.2dependency repair and is GREEN on SAST/Python Security/Security while CodeQL remains fail-closed on central verdict publication and current-head approval is missing. Canonical.github#2291@1794626af3473ef23b9c2e678c3f06fd6c11636fis GREEN on Runtime Quality/SAST/Security, fails Python Security only atpip-auditwhile inheriting protected AnyIO 4.14.0, and has nonterminal CodeQL. Neither owner delta may be copied into this Browser Session/BiDi lane.The former 21 September authority named #229
3ec6326b...and a 634-ahead/25-behind relationship. Earlier history named #229ce5074f..., #31754d7367..., and a 164-ahead/7-behind relationship. Those values are historical only and no longer define dependency authority.Required order is owner-first and acyclic: #212 central dependency/trusted-runtime/admission prerequisites → #229 current executable native CI/CodeQL/current-review/ruleset acceptance, with exact SAST/Security already GREEN → #317 ordinary non-force parent adoption preserving all valid deltas and current standards authority → #318/#321 ordered restack and parent-blob verification → #316 ACL/protocol proof integration → pinned-Chromium post-condition/destruction evidence under #292/#299. Do not patch parent-owned source or volatile standards metadata directly into #316.
Test-first acceptance
Screenadmission.Real Chromium transport, presentation observation, interaction outcome, restoration/destruction, and cleanup remain acceptance under #292/#299 after #212 supplies the protected workflow/sandbox contract. No self-approval, force push, destructive rebase, workflow/ruleset/secret mutation, runtime repin, gate weakening, tag, release, or publication is authorized here.