Skip to content

[Browser Session/BiDi ACL] Bind current lifecycle authority to presentation command planning #314

Description

@seonghobae

Gap and current owner

The Browser Session foundation introduced a non-caller-mintable lifecycle authority, but the product still needs a safe ACL from current live aggregate authority into the version-qualified originweave-bidi presentation planner. A public constructor or conversion from a retained PresentationMutationAuthority snapshot would reopen the authority gap: authority retained across epoch advance, navigation invalidation, destruction, transport loss, recovery, or session end could be planned after it became stale.

Historical #313 was merged into the #229 branch lineage; it is not the current Browser Session authority surface. The active deterministic Browser Session foundation is #317, and the active protocol-specific ACL/proof implementation lane is #316. Keep this issue open until that current lineage reaches executable exact-head acceptance and protected integration.

Browser Session remains lifecycle/policy authority; WebDriver BiDi remains an adapter. This issue does not own browser transport/sandbox mechanics, Keyverse, EgressWeave, contextual-orchestrator, Wardnet, download persistence, or real-browser release acceptance.

Required invariant

A BiDi presentation witness may be produced only from authority that the live BrowserSession aggregate has revalidated as current at the point of adapter use. The validation proof must be non-caller-constructible and bound to the owning aggregate/incarnation/context generation so stale or foreign authority cannot reach command planning or port I/O.

Raw BrowserSessionId, BrowsingContextId, DisposableIsolationId, protocol navigation id, or a retained PresentationMutationAuthority alone is insufficient. Command acknowledgement is not proof that presentation state was applied, restored, or destroyed.

Standards/runtime provenance boundary

Volatile WebDriver BiDi publication-currentness and the separately qualified OriginWeave runtime revision are owned by #229 and docs/traceability/webdriver-bidi-publication-current.md. This issue does not maintain a second dated latest/previous publication snapshot or silently repin runtime compatibility. #316 consumes only the admitted capability and owns the protocol-specific evidence semantics needed to project Browser Session authority.

Current dependency authority — 23 September 2026 KST

The former 21 September authority named #229 3ec6326b... and a 634-ahead/25-behind relationship. Earlier history named #229 ce5074f..., #317 54d7367..., and a 164-ahead/7-behind relationship. Those values are historical only and no longer define dependency authority.

Required order is owner-first and acyclic: #212 central dependency/trusted-runtime/admission prerequisites → #229 current executable native CI/CodeQL/current-review/ruleset acceptance, with exact SAST/Security already GREEN → #317 ordinary non-force parent adoption preserving all valid deltas and current standards authority → #318/#321 ordered restack and parent-blob verification → #316 ACL/protocol proof integration → pinned-Chromium post-condition/destruction evidence under #292/#299. Do not patch parent-owned source or volatile standards metadata directly into #316.

Test-first acceptance

  • RED: retain an authority token, advance the same context/navigation epoch, and prove the old token cannot be converted into a BiDi presentation witness or command plan.
  • RED: destroy the context, record transport loss/recovery, or end the session and prove no adapter witness can be derived from stale authority.
  • RED: authority from another aggregate with reused external session/context/epoch values but distinct incarnation/isolation must fail before any adapter command or transport path.
  • RED: a consumed navigation/recovery witness cannot be replayed to mint a second presentation opportunity.
  • GREEN: a current authority validated by the owning aggregate can be projected through one narrow ACL into the exact browsing-context-bound BiDi presentation witness and plan only the admitted viewport/DPR/timezone capability. Screen-area ownership remains separate and must not imply complete Screen admission.
  • GREEN proof boundary: command planning/ACK remains distinct from independently observed browser post-condition and from cleanup/destruction proof.
  • Keep Browser Session independent of WebDriver BiDi/CDP/MCP. The adapter may depend outward on a narrow Browser Session proof contract; Browser Session must not depend on adapter protocol types.
  • Owned production rustdoc, tests, edge cases, and function/line/region/branch coverage remain 100%.

Real Chromium transport, presentation observation, interaction outcome, restoration/destruction, and cleanup remain acceptance under #292/#299 after #212 supplies the protected workflow/sandbox contract. No self-approval, force push, destructive rebase, workflow/ruleset/secret mutation, runtime repin, gate weakening, tag, release, or publication is authorized here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions