Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
634 commits
Select commit Hold shift + click to select a range
7a95528
docs(browser-session): trace Cargo include authority
seonghobae Sep 18, 2026
5a63a00
test(browser-session): expose Cargo build-std provenance gap
seonghobae Sep 18, 2026
e524af3
fix(browser-session): fail closed on Cargo build-std authority
seonghobae Sep 18, 2026
2075d82
docs(browser-session): trace Cargo build-std provenance
seonghobae Sep 18, 2026
85954d3
test(browser-session): expose codegen backend provenance gap
seonghobae Sep 18, 2026
ff7d48b
fix(browser-session): fail closed on codegen backend authority
seonghobae Sep 18, 2026
61b6883
docs(browser-session): trace codegen backend authority
seonghobae Sep 18, 2026
9a7477e
test(browser-session): red custom target spec authority
seonghobae Sep 18, 2026
8e4db1b
fix(browser-session): reject custom target spec selection
seonghobae Sep 18, 2026
3ca29db
docs(browser-session): trace custom target spec authority
seonghobae Sep 18, 2026
6f2ee50
test(browser-session): model gated custom target spec
seonghobae Sep 18, 2026
0eaf527
docs(browser-session): align custom target gate evidence
seonghobae Sep 18, 2026
e7aafa5
test(browser-session): expose Cargo profile rustflags authority gap
seonghobae Sep 18, 2026
38c1c06
fix(browser-session): govern Cargo profile rustflags authority
seonghobae Sep 18, 2026
f482044
docs(browser-session): trace Cargo profile rustflags authority
seonghobae Sep 18, 2026
e87cab8
test(browser-session): add LLVM plugin authority RED
seonghobae Sep 18, 2026
60f27df
fix(browser-session): reject rustc LLVM pass plugin selection
seonghobae Sep 18, 2026
8440e5f
docs(browser-session): trace rustc LLVM plugin authority
seonghobae Sep 18, 2026
ab2fffa
test(browser-session): prove rustdoc doctest execution override gap
seonghobae Sep 18, 2026
d9c55cf
fix(browser-session): fail closed rustdoc doctest execution selectors
seonghobae Sep 18, 2026
0fd7fc8
docs(browser-session): trace rustdoc doctest execution authority
seonghobae Sep 18, 2026
eeb6944
test(browser-session): prove doctest build-arg provenance gap
seonghobae Sep 18, 2026
35733ea
fix(browser-session): classify doctest compiler forwarded authority
seonghobae Sep 18, 2026
e12677c
docs(browser-session): trace doctest build-arg authority
seonghobae Sep 18, 2026
8842bb0
test(browser-session): prove PGO profile input provenance gap
seonghobae Sep 18, 2026
76e8e89
fix(browser-session): govern PGO profile compiler inputs
seonghobae Sep 18, 2026
6fa0537
test(browser-session): cover rustdoc PGO input tunnels
seonghobae Sep 18, 2026
3ceb8fb
docs(browser-session): trace PGO profile input authority
seonghobae Sep 18, 2026
ef3455a
test(browser-session): RED direct LLVM option authority
seonghobae Sep 18, 2026
883f63a
fix(browser-session): fail closed on direct LLVM arguments
seonghobae Sep 18, 2026
59b504b
docs(browser-session): trace direct LLVM argument authority
seonghobae Sep 18, 2026
2f8233c
test(browser-session): red rustdoc render file inputs
seonghobae Sep 18, 2026
ab25968
fix(browser-session): reject rustdoc render file inputs
seonghobae Sep 18, 2026
a1d8a7f
test(browser-session): cover rustdoc render selectors
seonghobae Sep 18, 2026
02efe8c
docs(browser-session): trace rustdoc render file provenance
seonghobae Sep 18, 2026
a17cb3d
test(browser-session): red rustdoc index-page input
seonghobae Sep 18, 2026
54041d6
fix(browser-session): reject rustdoc index-page input
seonghobae Sep 18, 2026
5dda25c
test(browser-session): cover rustdoc index-page equals form
seonghobae Sep 18, 2026
8c17ecf
docs(browser-session): trace rustdoc index-page input
seonghobae Sep 18, 2026
b9103bd
test(browser-session): red rustdoc metadata input directories
seonghobae Sep 18, 2026
47ff437
fix(browser-session): reject rustdoc metadata inputs
seonghobae Sep 18, 2026
936ad92
docs(browser-session): trace rustdoc metadata input provenance
seonghobae Sep 18, 2026
3335612
docs(browser-session): align rustdoc documentation input owner
seonghobae Sep 18, 2026
f455739
test(browser-session): expose incremental cache provenance bypass
seonghobae Sep 18, 2026
6753b71
fix(browser-session): fail closed on incremental cache input
seonghobae Sep 18, 2026
580cbe3
docs(traceability): bind incremental cache provenance
seonghobae Sep 18, 2026
edbd3ee
test(browser-session): expose rustdoc library-path provenance gap
seonghobae Sep 18, 2026
ab1d09f
test(browser-session): assert rustdoc metadata policy marker
seonghobae Sep 18, 2026
34826a2
test(browser-session): assert rustdoc documentation marker
seonghobae Sep 18, 2026
f17413a
test(browser-session): assert doctest compiler authority marker
seonghobae Sep 18, 2026
fed5dd4
test(browser-session): assert doctest execution policy marker
seonghobae Sep 18, 2026
af11b31
fix(browser-session): classify rustdoc library-path inputs
seonghobae Sep 18, 2026
40cec6d
docs(browser-session): trace rustdoc library-path provenance repair
seonghobae Sep 18, 2026
cdec934
test(browser-session): fail closed on ambient host CPU codegen
seonghobae Sep 18, 2026
3dc8702
fix(browser-session): reject ambient host CPU codegen
seonghobae Sep 18, 2026
0eaa8e7
docs(browser-session): trace host CPU codegen authority
seonghobae Sep 18, 2026
a59f872
test(browser-session): expose LLD error-handler execution authority gap
seonghobae Sep 18, 2026
df9c025
fix(browser-session): reject LLD error-handler execution authority
seonghobae Sep 18, 2026
ccf217f
docs(traceability): record LLD error-handler execution boundary
seonghobae Sep 18, 2026
e86b8f5
test(browser-session): expose LLD DTLTO executable authority gap
seonghobae Sep 18, 2026
de49c23
fix(browser-session): reject LLD DTLTO executable authority
seonghobae Sep 18, 2026
aaa0466
docs(traceability): record LLD DTLTO execution boundary
seonghobae Sep 18, 2026
d4df3c8
test(browser-session): use canonical DTLTO contract naming
seonghobae Sep 18, 2026
1ce0eba
test(browser-session): remove misspelled DTLTO fixture path
seonghobae Sep 18, 2026
69ccddc
refactor(browser-session): use canonical DTLTO helper naming
seonghobae Sep 18, 2026
e1ef610
docs(traceability): normalize DTLTO repair lineage
seonghobae Sep 18, 2026
1af97ad
test(browser-session): expose linker sysroot input authority
seonghobae Sep 18, 2026
372f319
fix(browser-session): fail closed on linker sysroot inputs
seonghobae Sep 18, 2026
f38bbbc
docs(traceability): record linker sysroot input authority
seonghobae Sep 18, 2026
4b5297e
docs(changelog): record linker sysroot provenance guard
seonghobae Sep 18, 2026
6bd948f
test(browser-session): expose default linker script authority
seonghobae Sep 18, 2026
63f1252
fix(browser-session): fail closed on default linker scripts
seonghobae Sep 18, 2026
32f57db
docs(traceability): record default linker script authority
seonghobae Sep 18, 2026
da96259
docs(changelog): record default linker script provenance guard
seonghobae Sep 18, 2026
975e354
test(browser-session): expose MRI linker script authority
seonghobae Sep 18, 2026
5a066aa
fix(browser-session): fail closed on MRI linker scripts
seonghobae Sep 18, 2026
693d4a3
docs(traceability): record MRI linker script authority
seonghobae Sep 18, 2026
341ec73
docs(changelog): record MRI linker script provenance guard
seonghobae Sep 18, 2026
f271a2a
test(browser-session): expose linker just-symbols provenance bypass
seonghobae Sep 18, 2026
7b75fa3
fix(browser-session): fail closed on linker just-symbols inputs
seonghobae Sep 18, 2026
4e8fbcc
docs(browser-session): trace linker just-symbols authority
seonghobae Sep 18, 2026
84d3e08
test(browser-session): cover linker symbol-policy file authority
seonghobae Sep 18, 2026
ba239fa
fix(browser-session): fail closed on linker symbol-policy files
seonghobae Sep 18, 2026
e6abedd
docs(browser-session): trace linker symbol-policy file authority
seonghobae Sep 18, 2026
268f60c
docs(changelog): record linker provenance repairs
seonghobae Sep 18, 2026
0b68811
test(browser-session): reproduce runtime loader authority bypass
seonghobae Sep 18, 2026
132b6e1
test(browser-session): cover runtime loader suppression authority
seonghobae Sep 18, 2026
0d241f0
fix(browser-session): fail closed on runtime loader authority
seonghobae Sep 18, 2026
75334b8
docs(browser-session): trace runtime loader authority
seonghobae Sep 18, 2026
81b0515
test(browser-session): reproduce rtld-audit authority bypass
seonghobae Sep 18, 2026
4b25e4e
test(browser-session): cover GNU single-dash audit alias
seonghobae Sep 18, 2026
942c158
fix(browser-session): fail closed on rtld-audit authority
seonghobae Sep 18, 2026
db9b283
docs(browser-session): trace rtld-audit authority
seonghobae Sep 18, 2026
0168d40
test(browser-session): RED ELF runtime filter authority
seonghobae Sep 18, 2026
b7adc78
fix(browser-session): govern ELF runtime filter authority
seonghobae Sep 18, 2026
d905052
docs(browser-session): trace ELF runtime filter authority
seonghobae Sep 18, 2026
3551613
test(browser-session): RED preserve GNU ld fini selector
seonghobae Sep 18, 2026
2859254
fix(browser-session): preserve GNU ld fini selector
seonghobae Sep 18, 2026
bc7342f
docs(browser-session): record runtime filter compatibility correction
seonghobae Sep 18, 2026
12abc14
test(browser-session): RED linker runtime search-path authority
seonghobae Sep 18, 2026
a13f803
fix(browser-session): govern linker runtime search paths
seonghobae Sep 18, 2026
e05cfe7
docs(browser-session): trace linker runtime search-path authority
seonghobae Sep 18, 2026
b599ea4
test(browser-session): RED GNU ld default library search-path authority
seonghobae Sep 18, 2026
d467213
fix(browser-session): govern GNU ld default library search path
seonghobae Sep 18, 2026
43ce517
chore(browser-session): preserve compiler authority file formatting
seonghobae Sep 18, 2026
b60e27c
docs(traceability): record GNU ld default library search-path authority
seonghobae Sep 18, 2026
4cd6a1a
chore(traceability): terminate default search-path record cleanly
seonghobae Sep 18, 2026
763bcad
test(browser-session): reject LLD mllvm authority
seonghobae Sep 18, 2026
af934e5
fix(browser-session): fail closed on LLD mllvm forwarding
seonghobae Sep 18, 2026
a2900e8
docs(browser-session): trace LLD mllvm authority
seonghobae Sep 18, 2026
cbc4ac2
style(browser-session): restore compiler contract spacing
seonghobae Sep 18, 2026
c3416fa
test(browser-session): expose linker input-remap authority gap
seonghobae Sep 18, 2026
333195e
fix(browser-session): reject linker input remapping authority
seonghobae Sep 18, 2026
5e017bf
docs(traceability): record linker input-remap authority
seonghobae Sep 18, 2026
40f244c
test(browser-session): expose section-ordering script authority gap
seonghobae Sep 18, 2026
d33b5f7
fix(browser-session): reject section-ordering script authority
seonghobae Sep 18, 2026
84c4696
docs(traceability): record section-ordering script authority
seonghobae Sep 18, 2026
04a6079
test(browser-session): expose LLD layout profile input authority
seonghobae Sep 18, 2026
04da163
fix(browser-session): reject LLD layout profile inputs
seonghobae Sep 18, 2026
5654563
test(browser-session): cover LLD callgraph alias spelling
seonghobae Sep 18, 2026
a5c63c7
fix(browser-session): cover LLD callgraph alias spelling
seonghobae Sep 18, 2026
3797481
test(browser-session): expose LLD sample profile alias authority
seonghobae Sep 18, 2026
d6dc93f
fix(browser-session): reject LLD sample profile aliases
seonghobae Sep 18, 2026
b6e5694
docs(traceability): record LLD layout profile input authority
seonghobae Sep 18, 2026
934f695
test(security): reproduce LLD CMSE import library provenance bypass
seonghobae Sep 18, 2026
34cf801
test(security): keep CMSE import-library finding non-red until canoni…
seonghobae Sep 18, 2026
65511f4
docs(security): record LLD CMSE import-library provenance gap
seonghobae Sep 18, 2026
411ec41
test(browser-session): expose LLD CMSE import-library authority gap
seonghobae Sep 19, 2026
28ffd6f
fix(browser-session): classify LLD CMSE import-library input authority
seonghobae Sep 19, 2026
ab289d0
docs(browser-session): close CMSE import-library source repair trace
seonghobae Sep 19, 2026
9b23b72
test(browser-session): reject LLD context-sensitive profile inputs
seonghobae Sep 19, 2026
ea4cfea
fix(browser-session): fail closed on LLD CS profile inputs
seonghobae Sep 19, 2026
2d0fc8e
docs(browser-session): trace LLD context-sensitive profile authority
seonghobae Sep 19, 2026
95763aa
docs(changelog): record linker provenance repairs
seonghobae Sep 19, 2026
a182997
test(browser-session): expose ThinLTO cache authority bypass
seonghobae Sep 19, 2026
3808162
fix(browser-session): reject mutable ThinLTO cache inputs
seonghobae Sep 19, 2026
1807187
docs(traceability): record ThinLTO cache input authority
seonghobae Sep 19, 2026
3002600
test(browser-session): expose linker library alias authority bypass
seonghobae Sep 19, 2026
a168131
fix(browser-session): close linker library alias input authority
seonghobae Sep 19, 2026
59c9053
docs(browser-session): trace linker library alias authority
seonghobae Sep 19, 2026
89b611a
docs(changelog): record linker provenance closures
seonghobae Sep 19, 2026
a36e22d
test(browser-session): expose LLD plugin-opt LLVM authority
seonghobae Sep 19, 2026
64627f9
fix(browser-session): reject LLD plugin-opt LLVM tunnel
seonghobae Sep 19, 2026
57bde73
docs(browser-session): trace LLD plugin-opt LLVM authority
seonghobae Sep 19, 2026
b445b22
test(browser-session): expose LLD pass-plugin code loading
seonghobae Sep 19, 2026
3d0efa7
fix(browser-session): reject LLD pass-plugin loading
seonghobae Sep 19, 2026
dc2d062
docs(browser-session): trace LLD pass-plugin execution authority
seonghobae Sep 19, 2026
8634074
test(browser-session): expose LLD chroot input authority
seonghobae Sep 19, 2026
2d7c6e6
test(browser-session): drop already-covered LLD chroot probe
seonghobae Sep 19, 2026
fe84282
test(browser-session): expose DTLTO subprocess argument authority
seonghobae Sep 19, 2026
352c22b
test(browser-session): cover separated DTLTO subprocess args
seonghobae Sep 19, 2026
bb657a7
fix(browser-session): close DTLTO subprocess argument authority
seonghobae Sep 19, 2026
db69d56
docs(traceability): record DTLTO subprocess argument authority
seonghobae Sep 19, 2026
f37c9b3
docs(changelog): record linker execution provenance closures
seonghobae Sep 19, 2026
9024d61
test(browser-session): expose Rust native-link attribute provenance gap
seonghobae Sep 19, 2026
e3571e5
fix(browser-session): fail closed source-selected native libraries
seonghobae Sep 19, 2026
e7258ab
docs(browser-session): trace source-selected native library authority
seonghobae Sep 19, 2026
5ae81cc
test(browser-session): reproduce commented link attribute false positive
seonghobae Sep 19, 2026
efb8f1d
fix(browser-session): lex real Rust attributes before provenance checks
seonghobae Sep 19, 2026
84fc5b9
docs(browser-session): trace Rust attribute lexer root repair
seonghobae Sep 19, 2026
5cac6fe
test(browser-session): expose embedded file input gap
seonghobae Sep 19, 2026
c163991
fix(browser-session): govern Rust embedded file inputs
seonghobae Sep 19, 2026
c52ad3a
docs(browser-session): trace embedded Rust file inputs
seonghobae Sep 19, 2026
87eb778
test(browser-session): expose source environment input gap
seonghobae Sep 19, 2026
a6eec1a
fix(browser-session): govern source environment inputs
seonghobae Sep 19, 2026
75eb414
docs(browser-session): trace source environment inputs
seonghobae Sep 19, 2026
f9934fe
test(browser-session): close source environment lexical coverage
seonghobae Sep 19, 2026
f12499c
docs(browser-session): record source environment review closure
seonghobae Sep 19, 2026
fb2379a
docs(browser-session): record compile-time env re-review
seonghobae Sep 19, 2026
be925ec
docs(browser-session): record Rust source provenance fixes
seonghobae Sep 19, 2026
369b807
test(browser-session): expose aliased embedded-file macro bypass
seonghobae Sep 19, 2026
ae1cf87
fix(browser-session): reject aliased Rust embedded-file macros
seonghobae Sep 19, 2026
423c408
test(browser-session): cover underscore-prefixed embedded macro aliases
seonghobae Sep 19, 2026
b978c3c
fix(browser-session): distinguish underscore macro imports from aliases
seonghobae Sep 19, 2026
3f40f66
test(browser-session): harden embedded macro alias grammar coverage
seonghobae Sep 19, 2026
2c108fc
docs(traceability): record Rust embedded macro alias authority
seonghobae Sep 19, 2026
07841fb
test(browser-session): regress embedded alias lexical boundaries
seonghobae Sep 19, 2026
5dc7592
docs(traceability): record embedded alias lexical review repair
seonghobae Sep 19, 2026
6bf90e9
test(browser-session): expose include lexical false positive
seonghobae Sep 19, 2026
6ad8f19
fix(browser-session): make include authority lexical
seonghobae Sep 19, 2026
2f3311b
test(browser-session): cover include lexical edge cases
seonghobae Sep 19, 2026
4e4e217
docs(browser-session): trace include lexical authority
seonghobae Sep 19, 2026
6134c1b
test(browser-session): expose grouped-use comment alias false positive
seonghobae Sep 19, 2026
be35964
fix(browser-session): lex grouped include aliases
seonghobae Sep 19, 2026
84fb37d
docs(browser-session): record grouped-use lexical repair
seonghobae Sep 19, 2026
bd457be
test(browser-session): expose custom-target mod lexical false positive
seonghobae Sep 19, 2026
6f8b070
fix(browser-session): make custom-target mod detection lexical
seonghobae Sep 19, 2026
a4ab2ac
docs(browser-session): trace custom-target mod lexical repair
seonghobae Sep 19, 2026
a4ad6d4
test(browser-session): cover custom-target mod lexer edges
seonghobae Sep 19, 2026
c36f863
docs(browser-session): record custom-target mod edge coverage
seonghobae Sep 19, 2026
a214c87
test(browser-session): expose Rust XID mod boundary false positive
seonghobae Sep 19, 2026
ec32bd9
fix(browser-session): align mod keyword boundary with Rust Unicode
seonghobae Sep 19, 2026
df940ba
test(browser-session): cover Rust mod Unicode token boundaries
seonghobae Sep 19, 2026
ce33ae1
test(browser-session): expose Rust Pattern_White_Space trivia bypass
seonghobae Sep 19, 2026
e199aac
fix(browser-session): use Rust Pattern_White_Space in lexer
seonghobae Sep 19, 2026
2eb7475
docs(browser-session): trace Rust Unicode lexical root repair
seonghobae Sep 19, 2026
8e50e1c
test(browser-session): expose include XID boundary false positive
seonghobae Sep 19, 2026
a400e83
fix(browser-session): share Rust identifier boundary for include
seonghobae Sep 19, 2026
6f8da23
test(browser-session): expose include alias XID boundary false positive
seonghobae Sep 19, 2026
a827cc5
fix(browser-session): reuse Rust identifier boundary for include aliases
seonghobae Sep 19, 2026
67789f0
test(browser-session): expose path-meta lexical false positives
seonghobae Sep 19, 2026
79ad52c
fix(browser-session): lex path meta outside Rust data tokens
seonghobae Sep 19, 2026
e4385f3
docs(browser-session): trace path-meta lexical authority
seonghobae Sep 19, 2026
f8f6e66
test(browser-session): expose raw path attribute bypass
seonghobae Sep 19, 2026
debd5f6
fix(browser-session): recognize raw path attribute authority
seonghobae Sep 19, 2026
b59dd1b
docs(browser-session): trace raw path attribute authority
seonghobae Sep 19, 2026
6875cb1
docs(changelog): record Rust source provenance repairs
seonghobae Sep 19, 2026
960d361
test(browser-session): expose Cargo host-config authority gap
seonghobae Sep 19, 2026
da6b14d
fix(browser-session): govern Cargo host execution authority
seonghobae Sep 19, 2026
66d8a53
test(browser-session): cover Cargo host rustdoc and link overrides
seonghobae Sep 19, 2026
d2830dd
fix(browser-session): close Cargo host rustdoc and link-override auth…
seonghobae Sep 19, 2026
9fc512b
docs(traceability): bind Cargo host-config authority
seonghobae Sep 19, 2026
dadaf82
docs(changelog): record Cargo host-config authority
seonghobae Sep 19, 2026
6574faa
test(browser-session): expose generic Cargo host links override
seonghobae Sep 19, 2026
edfbd74
fix(browser-session): fail closed ambiguous Cargo host link tables
seonghobae Sep 19, 2026
0069162
docs(browser-session): trace generic Cargo host links authority
seonghobae Sep 19, 2026
a108eb4
test(browser-session): expose cfg-target links override false positive
seonghobae Sep 19, 2026
9b6191a
fix(browser-session): distinguish cfg target tables from links overrides
seonghobae Sep 19, 2026
acaa4cc
docs(traceability): distinguish cfg target from links override authority
seonghobae Sep 19, 2026
87e41f8
docs(bidi): refresh publication-current receipt
seonghobae Sep 19, 2026
1ab945a
test(bidi): bind publication observation date
seonghobae Sep 19, 2026
61d27ea
docs(changelog): record Cargo host and cfg-target semantics
seonghobae Sep 19, 2026
d52950e
test(browser-session): expose rustdoc with-examples provenance gap
seonghobae Sep 19, 2026
363a639
fix(browser-session): fail closed on rustdoc with-examples input
seonghobae Sep 19, 2026
5cf12bd
docs(traceability): record rustdoc with-examples input authority
seonghobae Sep 19, 2026
dad69ee
test(browser-session): cover host rustdoc with-examples authority
seonghobae Sep 19, 2026
181de85
docs(traceability): bind with-examples host coverage
seonghobae Sep 19, 2026
02edba7
docs(changelog): record rustdoc with-examples authority
seonghobae Sep 19, 2026
845d49b
test(browser-session): expose compile-time env macro alias bypass
seonghobae Sep 19, 2026
4830e42
fix(browser-session): reject aliased compile-time env macros
seonghobae Sep 19, 2026
19c466a
docs(browser-session): currentize custom-target lexical residuals
seonghobae Sep 19, 2026
32830c5
docs(browser-session): trace compile-time env macro aliases
seonghobae Sep 19, 2026
181be4b
fix(browser-session): preserve Unicode include aliases
seonghobae Sep 19, 2026
90fa45f
fix(browser-session): preserve Unicode embedded-file aliases
seonghobae Sep 19, 2026
ad71ca1
test(browser-session): expose host-triple false positive
seonghobae Sep 19, 2026
1e4c16d
fix(browser-session): distinguish host target settings from links ove…
seonghobae Sep 19, 2026
f85408e
test(browser-session): expose empty host links override
seonghobae Sep 19, 2026
7a72d83
fix(browser-session): reject empty host links overrides
seonghobae Sep 19, 2026
fa33f4e
docs(browser-session): trace empty host links authority
seonghobae Sep 19, 2026
f4dd6e5
test(browser-session): expose env macro Unicode boundary false positive
seonghobae Sep 19, 2026
2f960cb
fix(browser-session): use Rust identifier boundaries for env macros
seonghobae Sep 19, 2026
8c83413
docs(browser-session): trace env macro Rust identifier boundary repair
seonghobae Sep 19, 2026
550d8bf
test(browser-session): expose Rust use XID boundary false positive
seonghobae Sep 19, 2026
1f323bc
fix(browser-session): use Rust lexical boundaries for use aliases
seonghobae Sep 19, 2026
a8998b0
docs(browser-session): trace Rust use XID boundary repair
seonghobae Sep 19, 2026
8b98d08
test(browser-session): expose compile-time env use boundary regression
seonghobae Sep 19, 2026
c06a36d
fix(browser-session): share Rust use/as identifier boundaries
seonghobae Sep 19, 2026
7478246
docs(browser-session): trace compile-time env alias boundary repair
seonghobae Sep 19, 2026
01aa661
docs(changelog): record Rust XID and empty host override repairs
seonghobae Sep 20, 2026
70cc9d8
fix(changelog): restore trailing newline after documentation repair
seonghobae Sep 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,9 +151,9 @@ Owns the narrow WebDriver BiDi adapter contract that is expressible by one expli

### `originweave-browser-session` (active PR)

Owns the Browser Session aggregate boundary for disposable context lifecycle and presentation-mutation authority. Raw `BrowserSessionId` and `BrowsingContextId` values are transport addressability only. A context enters the owned set only after the narrow `DisposableContextPort` reports a fresh disposable isolation boundary together with its browsing-context address. The aggregate stores that exact handle and issues a non-caller-constructible `PresentationMutationAuthority` bound to browser-session identity, disposable-isolation identity, browsing context, and monotonic context epoch.
Owns the Browser Session aggregate boundary for disposable context lifecycle and presentation-mutation authority. Raw `BrowserSessionId` and `BrowsingContextId` values are transport addressability only. A context enters the owned set only after the narrow `DisposableContextPort` reports a fresh disposable isolation boundary together with its browsing-context address. The aggregate stores that exact handle and issues a non-caller-constructible `PresentationMutationAuthority` bound to browser-session identity, `BrowserSessionIncarnation`, disposable-isolation identity, browsing context, and monotonic context epoch. `BrowserSessionIncarnation` participates in authorization validation and prevents sequential ABA when external session/context identifiers and local epoch values are reused.

The isolation identity prevents distinct aggregate incarnations from aliasing authority when external session/context identifiers and local epoch values are reused. Destruction validates the full authority before adapter I/O and passes the stored isolation handle back to the port; cleanup authority is never reconstructed from `(BrowserSessionId, BrowsingContextId)`. For a WebDriver BiDi adapter, the port contract requires a one-to-one mapping from the domain's `DisposableIsolationId` to the specification-defined unique user-context id created for that live boundary. The protocol identifier is lifecycle addressability, not OriginWeave policy authority. Stale, foreign-session, foreign-isolation, unknown, destroyed, or uncertain authority fails closed; failed destruction makes the context uncertain; browser transport loss invalidates active authority; and normal session end is rejected until every owned boundary has proven destruction.
The disposable-isolation identity binds lifecycle ownership to the exact browser isolation boundary; it does not substitute for `BrowserSessionIncarnation`. Destruction validates the full authority before adapter I/O and passes the stored isolation handle back to the port; cleanup authority is never reconstructed from `(BrowserSessionId, BrowsingContextId)`. For a WebDriver BiDi adapter, the port contract requires a one-to-one mapping from the domain's `DisposableIsolationId` to the specification-defined unique user-context id created for that live boundary. The protocol identifier is lifecycle addressability, not OriginWeave policy authority. Stale, foreign-session, foreign-isolation, unknown, destroyed, or uncertain authority fails closed; failed destruction makes the context uncertain; browser transport loss invalidates active authority; and normal session end is rejected until every owned boundary has proven destruction.

This active slice deliberately stops before browser transport. WebDriver BiDi/CDP remain adapters and do not mint policy authority. The current proposal does not yet bridge domain authority into `originweave-bidi`'s private presentation/screen-area witnesses, implement the real `browser.createUserContext`/`browsingContext.create`/`browser.removeUserContext` adapter, prove exact-boundary cleanup post-conditions in Chromium, or establish protected-main behavior. ADR 0114, the Browser Session traceability dossier, and the lifecycle UML record those remaining boundaries.

Expand Down
54 changes: 51 additions & 3 deletions CHANGELOG.md

Large diffs are not rendered by default.

2,296 changes: 2,296 additions & 0 deletions crates/originweave-browser-session/src/browser_session.rs

Large diffs are not rendered by default.

1,031 changes: 25 additions & 1,006 deletions crates/originweave-browser-session/src/lib.rs

Large diffs are not rendered by default.

517 changes: 517 additions & 0 deletions crates/originweave-browser-session/src/recovery.rs

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,171 @@
use std::cell::{Cell, RefCell};
use std::rc::Rc;

use originweave_browser_session::{
AuthorizedContextOperationError, AuthorizedContextOperationPort,
AuthorizedContextOperationRequest, BrowserSession, BrowserSessionError,
BrowserSessionIncarnation, DisposableContextCreateCompletion,
DisposableContextCreateCompletionError, DisposableContextCreateError,
DisposableContextCreateRequest, DisposableContextDestroyError, DisposableContextDestroyRequest,
DisposableContextHandle, DisposableContextPort, DisposableIsolationId,
};
use originweave_core::{BrowserSessionId, BrowsingContextId};

struct OperationPort {
handle: Option<DisposableContextHandle>,
operation_calls: Rc<Cell<usize>>,
observed_operations: Rc<RefCell<Vec<&'static str>>>,
observed_sessions: Rc<RefCell<Vec<BrowserSessionId>>>,
observed_incarnations: Rc<RefCell<Vec<BrowserSessionIncarnation>>>,
observed_epochs: Rc<RefCell<Vec<u64>>>,
fail_operation: Rc<Cell<bool>>,
}

impl DisposableContextPort for OperationPort {
fn create_disposable_context(
&mut self,
_request: &DisposableContextCreateRequest,
) -> Result<DisposableContextHandle, DisposableContextCreateError> {
self.handle
.take()
.ok_or(DisposableContextCreateError::CreateFailedClean)
}

fn complete_disposable_context_creation(
&mut self,
_completion: &DisposableContextCreateCompletion,
) -> Result<(), DisposableContextCreateCompletionError> {
Ok(())
}

fn destroy_disposable_context(
&mut self,
_request: &DisposableContextDestroyRequest,
) -> Result<(), DisposableContextDestroyError> {
Ok(())
}
}

impl AuthorizedContextOperationPort for OperationPort {
type Operation = &'static str;
type Output = BrowsingContextId;
type Error = ();

fn execute_authorized_context_operation(
&mut self,
request: &AuthorizedContextOperationRequest<Self::Operation>,
) -> Result<Self::Output, Self::Error> {
self.operation_calls.set(self.operation_calls.get() + 1);
self.observed_operations
.borrow_mut()
.push(*request.operation());
self.observed_sessions
.borrow_mut()
.push(request.browser_session());
self.observed_incarnations
.borrow_mut()
.push(request.incarnation());
self.observed_epochs
.borrow_mut()
.push(request.context_epoch().value());
if self.fail_operation.get() {
Err(())
} else {
Ok(request.context().browsing_context())
}
}
}

#[test]
fn authorized_operation_uses_exact_bound_port_and_rejects_stale_authority_before_io() {
let operation_calls = Rc::new(Cell::new(0));
let observed_operations = Rc::new(RefCell::new(Vec::new()));
let observed_sessions = Rc::new(RefCell::new(Vec::new()));
let observed_incarnations = Rc::new(RefCell::new(Vec::new()));
let observed_epochs = Rc::new(RefCell::new(Vec::new()));
let fail_operation = Rc::new(Cell::new(false));
let context = BrowsingContextId::new(503).expect("valid browsing context");
let port = OperationPort {
handle: Some(DisposableContextHandle::new(
DisposableIsolationId::parse("operation-user-context-503").expect("valid isolation id"),
context,
)),
operation_calls: Rc::clone(&operation_calls),
observed_operations: Rc::clone(&observed_operations),
observed_sessions: Rc::clone(&observed_sessions),
observed_incarnations: Rc::clone(&observed_incarnations),
observed_epochs: Rc::clone(&observed_epochs),
fail_operation: Rc::clone(&fail_operation),
};
let session_id = BrowserSessionId::new(503).expect("valid session id");
let session = BrowserSession::start(session_id).expect("incarnation capacity");
let incarnation = session.incarnation();
let mut bound = session.bind_lifecycle_port(port);

let authority = bound
.create_disposable_context()
.expect("accepted disposable context");
assert_eq!(
bound.execute_authorized_context_operation(&authority, "set-viewport"),
Ok(context)
);
assert_eq!(operation_calls.get(), 1);
assert_eq!(observed_operations.borrow().as_slice(), &["set-viewport"]);
assert_eq!(observed_sessions.borrow().as_slice(), &[session_id]);
assert_eq!(observed_incarnations.borrow().as_slice(), &[incarnation]);
assert_eq!(observed_epochs.borrow().as_slice(), &[1]);

fail_operation.set(true);
assert_eq!(
bound.execute_authorized_context_operation(&authority, "remote-failure"),
Err(AuthorizedContextOperationError::Adapter(()))
);
assert_eq!(operation_calls.get(), 2);
assert_eq!(observed_epochs.borrow().as_slice(), &[1, 1]);
fail_operation.set(false);

let current = bound
.advance_context_epoch(context)
.expect("advance authority epoch");
assert_eq!(
bound.execute_authorized_context_operation(&authority, "stale-operation"),
Err(AuthorizedContextOperationError::BrowserSession(
BrowserSessionError::AuthorityMismatch
))
);
assert_eq!(
operation_calls.get(),
2,
"stale authority must fail before the bound adapter observes an operation"
);
assert_eq!(
observed_epochs.borrow().as_slice(),
&[1, 1],
"stale authority must not emit an adapter request or provenance epoch"
);

assert_eq!(
bound.execute_authorized_context_operation(&current, "reconcile-liveness"),
Ok(context)
);
assert_eq!(operation_calls.get(), 3);
assert_eq!(
observed_operations.borrow().as_slice(),
&["set-viewport", "remote-failure", "reconcile-liveness"]
);
assert_eq!(
observed_sessions.borrow().as_slice(),
&[session_id, session_id, session_id],
"the purpose-bounded adapter must observe only the bound Browser Session identity"
);
assert_eq!(
observed_incarnations.borrow().as_slice(),
&[incarnation, incarnation, incarnation],
"the purpose-bounded adapter must observe only the bound Browser Session incarnation"
);
assert_eq!(
observed_epochs.borrow().as_slice(),
&[1, 1, 2],
"adapter requests must retain the exact validated authority epoch"
);
}
187 changes: 187 additions & 0 deletions crates/originweave-browser-session/tests/bound_session_abandonment.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,187 @@
use std::cell::Cell;
use std::rc::Rc;
use std::sync::Mutex;

use originweave_browser_session::{
BrowserSession, BrowserSessionError, DisposableContextCreateCompletion,
DisposableContextCreateCompletionError, DisposableContextCreateError,
DisposableContextCreateRequest, DisposableContextDestroyError, DisposableContextDestroyRequest,
DisposableContextHandle, DisposableContextPort, DisposableIsolationId,
abandoned_bound_session_count,
};
use originweave_core::{BrowserSessionId, BrowsingContextId};

static ABANDONMENT_COUNTER_LOCK: Mutex<()> = Mutex::new(());

struct AbandonmentPort {
handle: Option<DisposableContextHandle>,
destroy_calls: Rc<Cell<usize>>,
}

impl DisposableContextPort for AbandonmentPort {
fn create_disposable_context(
&mut self,
_request: &DisposableContextCreateRequest,
) -> Result<DisposableContextHandle, DisposableContextCreateError> {
self.handle
.take()
.ok_or(DisposableContextCreateError::CreateFailedClean)
}

fn complete_disposable_context_creation(
&mut self,
_completion: &DisposableContextCreateCompletion,
) -> Result<(), DisposableContextCreateCompletionError> {
Ok(())
}

fn destroy_disposable_context(
&mut self,
_request: &DisposableContextDestroyRequest,
) -> Result<(), DisposableContextDestroyError> {
self.destroy_calls.set(self.destroy_calls.get() + 1);
Ok(())
}
}

fn port_for(context: u64, destroy_calls: &Rc<Cell<usize>>) -> AbandonmentPort {
AbandonmentPort {
handle: Some(DisposableContextHandle::new(
DisposableIsolationId::parse(&format!("abandoned-user-context-{context}"))
.expect("valid isolation id"),
BrowsingContextId::new(context).expect("valid browsing context"),
)),
destroy_calls: Rc::clone(destroy_calls),
}
}

#[test]
fn dropping_unresolved_bound_session_is_observable_without_implicit_browser_io() {
let _guard = ABANDONMENT_COUNTER_LOCK
.lock()
.expect("abandonment counter test lock");
let destroy_calls = Rc::new(Cell::new(0));
let before = abandoned_bound_session_count();
let session = BrowserSession::start(BrowserSessionId::new(504).expect("valid session id"))
.expect("incarnation capacity");
let mut bound = session.bind_lifecycle_port(port_for(504, &destroy_calls));
let _authority = bound
.create_disposable_context()
.expect("accepted disposable context");

drop(bound);

assert_eq!(
destroy_calls.get(),
0,
"Drop must never pretend synchronous browser cleanup succeeded"
);
assert!(
abandoned_bound_session_count() > before,
"unresolved bound-session abandonment must be observable to recovery/operability code"
);
}

#[test]
fn transport_loss_without_remote_ownership_is_not_counted_as_abandonment() {
let _guard = ABANDONMENT_COUNTER_LOCK
.lock()
.expect("abandonment counter test lock");
let destroy_calls = Rc::new(Cell::new(0));
let before = abandoned_bound_session_count();

let empty_session = BrowserSession::start(BrowserSessionId::new(507).expect("valid session id"))
.expect("incarnation capacity");
let mut empty_bound = empty_session.bind_lifecycle_port(port_for(507, &destroy_calls));
assert!(empty_bound.record_transport_loss());
drop(empty_bound);
assert_eq!(
abandoned_bound_session_count(),
before,
"transport loss with no owned or uncertain browser context is not unresolved remote ownership"
);

let session = BrowserSession::start(BrowserSessionId::new(508).expect("valid session id"))
.expect("incarnation capacity");
let mut bound = session.bind_lifecycle_port(port_for(508, &destroy_calls));
let authority = bound
.create_disposable_context()
.expect("accepted disposable context");
bound
.destroy_disposable_context(&authority)
.expect("proven destruction");
assert!(bound.record_transport_loss());
drop(bound);

assert_eq!(destroy_calls.get(), 1);
assert_eq!(
abandoned_bound_session_count(),
before,
"transport loss after all remote ownership was proven destroyed must not create a false abandonment signal"
);
}

#[test]
fn failed_finish_retains_same_bound_owner_for_cleanup_and_retry() {
let _guard = ABANDONMENT_COUNTER_LOCK
.lock()
.expect("abandonment counter test lock");
let destroy_calls = Rc::new(Cell::new(0));
let before = abandoned_bound_session_count();
let session = BrowserSession::start(BrowserSessionId::new(506).expect("valid session id"))
.expect("incarnation capacity");
let mut bound = session.bind_lifecycle_port(port_for(506, &destroy_calls));
let authority = bound
.create_disposable_context()
.expect("accepted disposable context");

assert_eq!(
bound.finish(),
Err(BrowserSessionError::ActiveContextRemains)
);
assert_eq!(
abandoned_bound_session_count(),
before,
"a failed deliberate finish must retain the bound lifecycle owner instead of dropping it as abandonment"
);
assert_eq!(
destroy_calls.get(),
0,
"failed finish validation must not perform implicit browser cleanup"
);

bound
.destroy_disposable_context(&authority)
.expect("the same bound lifecycle owner must remain available for cleanup");
assert_eq!(destroy_calls.get(), 1);
bound
.finish()
.expect("retry succeeds after proven destruction");
drop(bound);
assert_eq!(
abandoned_bound_session_count(),
before,
"successful retry must leave no abandonment signal"
);
}

#[test]
fn proven_destruction_can_finish_without_abandonment_path() {
let _guard = ABANDONMENT_COUNTER_LOCK
.lock()
.expect("abandonment counter test lock");
let destroy_calls = Rc::new(Cell::new(0));
let session = BrowserSession::start(BrowserSessionId::new(505).expect("valid session id"))
.expect("incarnation capacity");
let mut bound = session.bind_lifecycle_port(port_for(505, &destroy_calls));
let authority = bound
.create_disposable_context()
.expect("accepted disposable context");
bound
.destroy_disposable_context(&authority)
.expect("proven destruction");
bound
.finish()
.expect("end normally after proven destruction");
assert_eq!(destroy_calls.get(), 1);
}
Loading