Skip to content
Draft
Show file tree
Hide file tree
Changes from 4 commits
Commits
Show all changes
634 commits
Select commit Hold shift + click to select a range
7a95528
docs(browser-session): trace Cargo include authority
seonghobae Sep 18, 2026
5a63a00
test(browser-session): expose Cargo build-std provenance gap
seonghobae Sep 18, 2026
e524af3
fix(browser-session): fail closed on Cargo build-std authority
seonghobae Sep 18, 2026
2075d82
docs(browser-session): trace Cargo build-std provenance
seonghobae Sep 18, 2026
85954d3
test(browser-session): expose codegen backend provenance gap
seonghobae Sep 18, 2026
ff7d48b
fix(browser-session): fail closed on codegen backend authority
seonghobae Sep 18, 2026
61b6883
docs(browser-session): trace codegen backend authority
seonghobae Sep 18, 2026
9a7477e
test(browser-session): red custom target spec authority
seonghobae Sep 18, 2026
8e4db1b
fix(browser-session): reject custom target spec selection
seonghobae Sep 18, 2026
3ca29db
docs(browser-session): trace custom target spec authority
seonghobae Sep 18, 2026
6f2ee50
test(browser-session): model gated custom target spec
seonghobae Sep 18, 2026
0eaf527
docs(browser-session): align custom target gate evidence
seonghobae Sep 18, 2026
e7aafa5
test(browser-session): expose Cargo profile rustflags authority gap
seonghobae Sep 18, 2026
38c1c06
fix(browser-session): govern Cargo profile rustflags authority
seonghobae Sep 18, 2026
f482044
docs(browser-session): trace Cargo profile rustflags authority
seonghobae Sep 18, 2026
e87cab8
test(browser-session): add LLVM plugin authority RED
seonghobae Sep 18, 2026
60f27df
fix(browser-session): reject rustc LLVM pass plugin selection
seonghobae Sep 18, 2026
8440e5f
docs(browser-session): trace rustc LLVM plugin authority
seonghobae Sep 18, 2026
ab2fffa
test(browser-session): prove rustdoc doctest execution override gap
seonghobae Sep 18, 2026
d9c55cf
fix(browser-session): fail closed rustdoc doctest execution selectors
seonghobae Sep 18, 2026
0fd7fc8
docs(browser-session): trace rustdoc doctest execution authority
seonghobae Sep 18, 2026
eeb6944
test(browser-session): prove doctest build-arg provenance gap
seonghobae Sep 18, 2026
35733ea
fix(browser-session): classify doctest compiler forwarded authority
seonghobae Sep 18, 2026
e12677c
docs(browser-session): trace doctest build-arg authority
seonghobae Sep 18, 2026
8842bb0
test(browser-session): prove PGO profile input provenance gap
seonghobae Sep 18, 2026
76e8e89
fix(browser-session): govern PGO profile compiler inputs
seonghobae Sep 18, 2026
6fa0537
test(browser-session): cover rustdoc PGO input tunnels
seonghobae Sep 18, 2026
3ceb8fb
docs(browser-session): trace PGO profile input authority
seonghobae Sep 18, 2026
ef3455a
test(browser-session): RED direct LLVM option authority
seonghobae Sep 18, 2026
883f63a
fix(browser-session): fail closed on direct LLVM arguments
seonghobae Sep 18, 2026
59b504b
docs(browser-session): trace direct LLVM argument authority
seonghobae Sep 18, 2026
2f8233c
test(browser-session): red rustdoc render file inputs
seonghobae Sep 18, 2026
ab25968
fix(browser-session): reject rustdoc render file inputs
seonghobae Sep 18, 2026
a1d8a7f
test(browser-session): cover rustdoc render selectors
seonghobae Sep 18, 2026
02efe8c
docs(browser-session): trace rustdoc render file provenance
seonghobae Sep 18, 2026
a17cb3d
test(browser-session): red rustdoc index-page input
seonghobae Sep 18, 2026
54041d6
fix(browser-session): reject rustdoc index-page input
seonghobae Sep 18, 2026
5dda25c
test(browser-session): cover rustdoc index-page equals form
seonghobae Sep 18, 2026
8c17ecf
docs(browser-session): trace rustdoc index-page input
seonghobae Sep 18, 2026
b9103bd
test(browser-session): red rustdoc metadata input directories
seonghobae Sep 18, 2026
47ff437
fix(browser-session): reject rustdoc metadata inputs
seonghobae Sep 18, 2026
936ad92
docs(browser-session): trace rustdoc metadata input provenance
seonghobae Sep 18, 2026
3335612
docs(browser-session): align rustdoc documentation input owner
seonghobae Sep 18, 2026
f455739
test(browser-session): expose incremental cache provenance bypass
seonghobae Sep 18, 2026
6753b71
fix(browser-session): fail closed on incremental cache input
seonghobae Sep 18, 2026
580cbe3
docs(traceability): bind incremental cache provenance
seonghobae Sep 18, 2026
edbd3ee
test(browser-session): expose rustdoc library-path provenance gap
seonghobae Sep 18, 2026
ab1d09f
test(browser-session): assert rustdoc metadata policy marker
seonghobae Sep 18, 2026
34826a2
test(browser-session): assert rustdoc documentation marker
seonghobae Sep 18, 2026
f17413a
test(browser-session): assert doctest compiler authority marker
seonghobae Sep 18, 2026
fed5dd4
test(browser-session): assert doctest execution policy marker
seonghobae Sep 18, 2026
af11b31
fix(browser-session): classify rustdoc library-path inputs
seonghobae Sep 18, 2026
40cec6d
docs(browser-session): trace rustdoc library-path provenance repair
seonghobae Sep 18, 2026
cdec934
test(browser-session): fail closed on ambient host CPU codegen
seonghobae Sep 18, 2026
3dc8702
fix(browser-session): reject ambient host CPU codegen
seonghobae Sep 18, 2026
0eaa8e7
docs(browser-session): trace host CPU codegen authority
seonghobae Sep 18, 2026
a59f872
test(browser-session): expose LLD error-handler execution authority gap
seonghobae Sep 18, 2026
df9c025
fix(browser-session): reject LLD error-handler execution authority
seonghobae Sep 18, 2026
ccf217f
docs(traceability): record LLD error-handler execution boundary
seonghobae Sep 18, 2026
e86b8f5
test(browser-session): expose LLD DTLTO executable authority gap
seonghobae Sep 18, 2026
de49c23
fix(browser-session): reject LLD DTLTO executable authority
seonghobae Sep 18, 2026
aaa0466
docs(traceability): record LLD DTLTO execution boundary
seonghobae Sep 18, 2026
d4df3c8
test(browser-session): use canonical DTLTO contract naming
seonghobae Sep 18, 2026
1ce0eba
test(browser-session): remove misspelled DTLTO fixture path
seonghobae Sep 18, 2026
69ccddc
refactor(browser-session): use canonical DTLTO helper naming
seonghobae Sep 18, 2026
e1ef610
docs(traceability): normalize DTLTO repair lineage
seonghobae Sep 18, 2026
1af97ad
test(browser-session): expose linker sysroot input authority
seonghobae Sep 18, 2026
372f319
fix(browser-session): fail closed on linker sysroot inputs
seonghobae Sep 18, 2026
f38bbbc
docs(traceability): record linker sysroot input authority
seonghobae Sep 18, 2026
4b5297e
docs(changelog): record linker sysroot provenance guard
seonghobae Sep 18, 2026
6bd948f
test(browser-session): expose default linker script authority
seonghobae Sep 18, 2026
63f1252
fix(browser-session): fail closed on default linker scripts
seonghobae Sep 18, 2026
32f57db
docs(traceability): record default linker script authority
seonghobae Sep 18, 2026
da96259
docs(changelog): record default linker script provenance guard
seonghobae Sep 18, 2026
975e354
test(browser-session): expose MRI linker script authority
seonghobae Sep 18, 2026
5a066aa
fix(browser-session): fail closed on MRI linker scripts
seonghobae Sep 18, 2026
693d4a3
docs(traceability): record MRI linker script authority
seonghobae Sep 18, 2026
341ec73
docs(changelog): record MRI linker script provenance guard
seonghobae Sep 18, 2026
f271a2a
test(browser-session): expose linker just-symbols provenance bypass
seonghobae Sep 18, 2026
7b75fa3
fix(browser-session): fail closed on linker just-symbols inputs
seonghobae Sep 18, 2026
4e8fbcc
docs(browser-session): trace linker just-symbols authority
seonghobae Sep 18, 2026
84d3e08
test(browser-session): cover linker symbol-policy file authority
seonghobae Sep 18, 2026
ba239fa
fix(browser-session): fail closed on linker symbol-policy files
seonghobae Sep 18, 2026
e6abedd
docs(browser-session): trace linker symbol-policy file authority
seonghobae Sep 18, 2026
268f60c
docs(changelog): record linker provenance repairs
seonghobae Sep 18, 2026
0b68811
test(browser-session): reproduce runtime loader authority bypass
seonghobae Sep 18, 2026
132b6e1
test(browser-session): cover runtime loader suppression authority
seonghobae Sep 18, 2026
0d241f0
fix(browser-session): fail closed on runtime loader authority
seonghobae Sep 18, 2026
75334b8
docs(browser-session): trace runtime loader authority
seonghobae Sep 18, 2026
81b0515
test(browser-session): reproduce rtld-audit authority bypass
seonghobae Sep 18, 2026
4b25e4e
test(browser-session): cover GNU single-dash audit alias
seonghobae Sep 18, 2026
942c158
fix(browser-session): fail closed on rtld-audit authority
seonghobae Sep 18, 2026
db9b283
docs(browser-session): trace rtld-audit authority
seonghobae Sep 18, 2026
0168d40
test(browser-session): RED ELF runtime filter authority
seonghobae Sep 18, 2026
b7adc78
fix(browser-session): govern ELF runtime filter authority
seonghobae Sep 18, 2026
d905052
docs(browser-session): trace ELF runtime filter authority
seonghobae Sep 18, 2026
3551613
test(browser-session): RED preserve GNU ld fini selector
seonghobae Sep 18, 2026
2859254
fix(browser-session): preserve GNU ld fini selector
seonghobae Sep 18, 2026
bc7342f
docs(browser-session): record runtime filter compatibility correction
seonghobae Sep 18, 2026
12abc14
test(browser-session): RED linker runtime search-path authority
seonghobae Sep 18, 2026
a13f803
fix(browser-session): govern linker runtime search paths
seonghobae Sep 18, 2026
e05cfe7
docs(browser-session): trace linker runtime search-path authority
seonghobae Sep 18, 2026
b599ea4
test(browser-session): RED GNU ld default library search-path authority
seonghobae Sep 18, 2026
d467213
fix(browser-session): govern GNU ld default library search path
seonghobae Sep 18, 2026
43ce517
chore(browser-session): preserve compiler authority file formatting
seonghobae Sep 18, 2026
b60e27c
docs(traceability): record GNU ld default library search-path authority
seonghobae Sep 18, 2026
4cd6a1a
chore(traceability): terminate default search-path record cleanly
seonghobae Sep 18, 2026
763bcad
test(browser-session): reject LLD mllvm authority
seonghobae Sep 18, 2026
af934e5
fix(browser-session): fail closed on LLD mllvm forwarding
seonghobae Sep 18, 2026
a2900e8
docs(browser-session): trace LLD mllvm authority
seonghobae Sep 18, 2026
cbc4ac2
style(browser-session): restore compiler contract spacing
seonghobae Sep 18, 2026
c3416fa
test(browser-session): expose linker input-remap authority gap
seonghobae Sep 18, 2026
333195e
fix(browser-session): reject linker input remapping authority
seonghobae Sep 18, 2026
5e017bf
docs(traceability): record linker input-remap authority
seonghobae Sep 18, 2026
40f244c
test(browser-session): expose section-ordering script authority gap
seonghobae Sep 18, 2026
d33b5f7
fix(browser-session): reject section-ordering script authority
seonghobae Sep 18, 2026
84c4696
docs(traceability): record section-ordering script authority
seonghobae Sep 18, 2026
04a6079
test(browser-session): expose LLD layout profile input authority
seonghobae Sep 18, 2026
04da163
fix(browser-session): reject LLD layout profile inputs
seonghobae Sep 18, 2026
5654563
test(browser-session): cover LLD callgraph alias spelling
seonghobae Sep 18, 2026
a5c63c7
fix(browser-session): cover LLD callgraph alias spelling
seonghobae Sep 18, 2026
3797481
test(browser-session): expose LLD sample profile alias authority
seonghobae Sep 18, 2026
d6dc93f
fix(browser-session): reject LLD sample profile aliases
seonghobae Sep 18, 2026
b6e5694
docs(traceability): record LLD layout profile input authority
seonghobae Sep 18, 2026
934f695
test(security): reproduce LLD CMSE import library provenance bypass
seonghobae Sep 18, 2026
34cf801
test(security): keep CMSE import-library finding non-red until canoni…
seonghobae Sep 18, 2026
65511f4
docs(security): record LLD CMSE import-library provenance gap
seonghobae Sep 18, 2026
411ec41
test(browser-session): expose LLD CMSE import-library authority gap
seonghobae Sep 19, 2026
28ffd6f
fix(browser-session): classify LLD CMSE import-library input authority
seonghobae Sep 19, 2026
ab289d0
docs(browser-session): close CMSE import-library source repair trace
seonghobae Sep 19, 2026
9b23b72
test(browser-session): reject LLD context-sensitive profile inputs
seonghobae Sep 19, 2026
ea4cfea
fix(browser-session): fail closed on LLD CS profile inputs
seonghobae Sep 19, 2026
2d0fc8e
docs(browser-session): trace LLD context-sensitive profile authority
seonghobae Sep 19, 2026
95763aa
docs(changelog): record linker provenance repairs
seonghobae Sep 19, 2026
a182997
test(browser-session): expose ThinLTO cache authority bypass
seonghobae Sep 19, 2026
3808162
fix(browser-session): reject mutable ThinLTO cache inputs
seonghobae Sep 19, 2026
1807187
docs(traceability): record ThinLTO cache input authority
seonghobae Sep 19, 2026
3002600
test(browser-session): expose linker library alias authority bypass
seonghobae Sep 19, 2026
a168131
fix(browser-session): close linker library alias input authority
seonghobae Sep 19, 2026
59c9053
docs(browser-session): trace linker library alias authority
seonghobae Sep 19, 2026
89b611a
docs(changelog): record linker provenance closures
seonghobae Sep 19, 2026
a36e22d
test(browser-session): expose LLD plugin-opt LLVM authority
seonghobae Sep 19, 2026
64627f9
fix(browser-session): reject LLD plugin-opt LLVM tunnel
seonghobae Sep 19, 2026
57bde73
docs(browser-session): trace LLD plugin-opt LLVM authority
seonghobae Sep 19, 2026
b445b22
test(browser-session): expose LLD pass-plugin code loading
seonghobae Sep 19, 2026
3d0efa7
fix(browser-session): reject LLD pass-plugin loading
seonghobae Sep 19, 2026
dc2d062
docs(browser-session): trace LLD pass-plugin execution authority
seonghobae Sep 19, 2026
8634074
test(browser-session): expose LLD chroot input authority
seonghobae Sep 19, 2026
2d7c6e6
test(browser-session): drop already-covered LLD chroot probe
seonghobae Sep 19, 2026
fe84282
test(browser-session): expose DTLTO subprocess argument authority
seonghobae Sep 19, 2026
352c22b
test(browser-session): cover separated DTLTO subprocess args
seonghobae Sep 19, 2026
bb657a7
fix(browser-session): close DTLTO subprocess argument authority
seonghobae Sep 19, 2026
db69d56
docs(traceability): record DTLTO subprocess argument authority
seonghobae Sep 19, 2026
f37c9b3
docs(changelog): record linker execution provenance closures
seonghobae Sep 19, 2026
9024d61
test(browser-session): expose Rust native-link attribute provenance gap
seonghobae Sep 19, 2026
e3571e5
fix(browser-session): fail closed source-selected native libraries
seonghobae Sep 19, 2026
e7258ab
docs(browser-session): trace source-selected native library authority
seonghobae Sep 19, 2026
5ae81cc
test(browser-session): reproduce commented link attribute false positive
seonghobae Sep 19, 2026
efb8f1d
fix(browser-session): lex real Rust attributes before provenance checks
seonghobae Sep 19, 2026
84fc5b9
docs(browser-session): trace Rust attribute lexer root repair
seonghobae Sep 19, 2026
5cac6fe
test(browser-session): expose embedded file input gap
seonghobae Sep 19, 2026
c163991
fix(browser-session): govern Rust embedded file inputs
seonghobae Sep 19, 2026
c52ad3a
docs(browser-session): trace embedded Rust file inputs
seonghobae Sep 19, 2026
87eb778
test(browser-session): expose source environment input gap
seonghobae Sep 19, 2026
a6eec1a
fix(browser-session): govern source environment inputs
seonghobae Sep 19, 2026
75eb414
docs(browser-session): trace source environment inputs
seonghobae Sep 19, 2026
f9934fe
test(browser-session): close source environment lexical coverage
seonghobae Sep 19, 2026
f12499c
docs(browser-session): record source environment review closure
seonghobae Sep 19, 2026
fb2379a
docs(browser-session): record compile-time env re-review
seonghobae Sep 19, 2026
be925ec
docs(browser-session): record Rust source provenance fixes
seonghobae Sep 19, 2026
369b807
test(browser-session): expose aliased embedded-file macro bypass
seonghobae Sep 19, 2026
ae1cf87
fix(browser-session): reject aliased Rust embedded-file macros
seonghobae Sep 19, 2026
423c408
test(browser-session): cover underscore-prefixed embedded macro aliases
seonghobae Sep 19, 2026
b978c3c
fix(browser-session): distinguish underscore macro imports from aliases
seonghobae Sep 19, 2026
3f40f66
test(browser-session): harden embedded macro alias grammar coverage
seonghobae Sep 19, 2026
2c108fc
docs(traceability): record Rust embedded macro alias authority
seonghobae Sep 19, 2026
07841fb
test(browser-session): regress embedded alias lexical boundaries
seonghobae Sep 19, 2026
5dc7592
docs(traceability): record embedded alias lexical review repair
seonghobae Sep 19, 2026
6bf90e9
test(browser-session): expose include lexical false positive
seonghobae Sep 19, 2026
6ad8f19
fix(browser-session): make include authority lexical
seonghobae Sep 19, 2026
2f3311b
test(browser-session): cover include lexical edge cases
seonghobae Sep 19, 2026
4e4e217
docs(browser-session): trace include lexical authority
seonghobae Sep 19, 2026
6134c1b
test(browser-session): expose grouped-use comment alias false positive
seonghobae Sep 19, 2026
be35964
fix(browser-session): lex grouped include aliases
seonghobae Sep 19, 2026
84fb37d
docs(browser-session): record grouped-use lexical repair
seonghobae Sep 19, 2026
bd457be
test(browser-session): expose custom-target mod lexical false positive
seonghobae Sep 19, 2026
6f8b070
fix(browser-session): make custom-target mod detection lexical
seonghobae Sep 19, 2026
a4ab2ac
docs(browser-session): trace custom-target mod lexical repair
seonghobae Sep 19, 2026
a4ad6d4
test(browser-session): cover custom-target mod lexer edges
seonghobae Sep 19, 2026
c36f863
docs(browser-session): record custom-target mod edge coverage
seonghobae Sep 19, 2026
a214c87
test(browser-session): expose Rust XID mod boundary false positive
seonghobae Sep 19, 2026
ec32bd9
fix(browser-session): align mod keyword boundary with Rust Unicode
seonghobae Sep 19, 2026
df940ba
test(browser-session): cover Rust mod Unicode token boundaries
seonghobae Sep 19, 2026
ce33ae1
test(browser-session): expose Rust Pattern_White_Space trivia bypass
seonghobae Sep 19, 2026
e199aac
fix(browser-session): use Rust Pattern_White_Space in lexer
seonghobae Sep 19, 2026
2eb7475
docs(browser-session): trace Rust Unicode lexical root repair
seonghobae Sep 19, 2026
8e50e1c
test(browser-session): expose include XID boundary false positive
seonghobae Sep 19, 2026
a400e83
fix(browser-session): share Rust identifier boundary for include
seonghobae Sep 19, 2026
6f8da23
test(browser-session): expose include alias XID boundary false positive
seonghobae Sep 19, 2026
a827cc5
fix(browser-session): reuse Rust identifier boundary for include aliases
seonghobae Sep 19, 2026
67789f0
test(browser-session): expose path-meta lexical false positives
seonghobae Sep 19, 2026
79ad52c
fix(browser-session): lex path meta outside Rust data tokens
seonghobae Sep 19, 2026
e4385f3
docs(browser-session): trace path-meta lexical authority
seonghobae Sep 19, 2026
f8f6e66
test(browser-session): expose raw path attribute bypass
seonghobae Sep 19, 2026
debd5f6
fix(browser-session): recognize raw path attribute authority
seonghobae Sep 19, 2026
b59dd1b
docs(browser-session): trace raw path attribute authority
seonghobae Sep 19, 2026
6875cb1
docs(changelog): record Rust source provenance repairs
seonghobae Sep 19, 2026
960d361
test(browser-session): expose Cargo host-config authority gap
seonghobae Sep 19, 2026
da6b14d
fix(browser-session): govern Cargo host execution authority
seonghobae Sep 19, 2026
66d8a53
test(browser-session): cover Cargo host rustdoc and link overrides
seonghobae Sep 19, 2026
d2830dd
fix(browser-session): close Cargo host rustdoc and link-override auth…
seonghobae Sep 19, 2026
9fc512b
docs(traceability): bind Cargo host-config authority
seonghobae Sep 19, 2026
dadaf82
docs(changelog): record Cargo host-config authority
seonghobae Sep 19, 2026
6574faa
test(browser-session): expose generic Cargo host links override
seonghobae Sep 19, 2026
edfbd74
fix(browser-session): fail closed ambiguous Cargo host link tables
seonghobae Sep 19, 2026
0069162
docs(browser-session): trace generic Cargo host links authority
seonghobae Sep 19, 2026
a108eb4
test(browser-session): expose cfg-target links override false positive
seonghobae Sep 19, 2026
9b6191a
fix(browser-session): distinguish cfg target tables from links overrides
seonghobae Sep 19, 2026
acaa4cc
docs(traceability): distinguish cfg target from links override authority
seonghobae Sep 19, 2026
87e41f8
docs(bidi): refresh publication-current receipt
seonghobae Sep 19, 2026
1ab945a
test(bidi): bind publication observation date
seonghobae Sep 19, 2026
61d27ea
docs(changelog): record Cargo host and cfg-target semantics
seonghobae Sep 19, 2026
d52950e
test(browser-session): expose rustdoc with-examples provenance gap
seonghobae Sep 19, 2026
363a639
fix(browser-session): fail closed on rustdoc with-examples input
seonghobae Sep 19, 2026
5cf12bd
docs(traceability): record rustdoc with-examples input authority
seonghobae Sep 19, 2026
dad69ee
test(browser-session): cover host rustdoc with-examples authority
seonghobae Sep 19, 2026
181de85
docs(traceability): bind with-examples host coverage
seonghobae Sep 19, 2026
02edba7
docs(changelog): record rustdoc with-examples authority
seonghobae Sep 19, 2026
845d49b
test(browser-session): expose compile-time env macro alias bypass
seonghobae Sep 19, 2026
4830e42
fix(browser-session): reject aliased compile-time env macros
seonghobae Sep 19, 2026
19c466a
docs(browser-session): currentize custom-target lexical residuals
seonghobae Sep 19, 2026
32830c5
docs(browser-session): trace compile-time env macro aliases
seonghobae Sep 19, 2026
181be4b
fix(browser-session): preserve Unicode include aliases
seonghobae Sep 19, 2026
90fa45f
fix(browser-session): preserve Unicode embedded-file aliases
seonghobae Sep 19, 2026
ad71ca1
test(browser-session): expose host-triple false positive
seonghobae Sep 19, 2026
1e4c16d
fix(browser-session): distinguish host target settings from links ove…
seonghobae Sep 19, 2026
f85408e
test(browser-session): expose empty host links override
seonghobae Sep 19, 2026
7a72d83
fix(browser-session): reject empty host links overrides
seonghobae Sep 19, 2026
fa33f4e
docs(browser-session): trace empty host links authority
seonghobae Sep 19, 2026
f4dd6e5
test(browser-session): expose env macro Unicode boundary false positive
seonghobae Sep 19, 2026
2f960cb
fix(browser-session): use Rust identifier boundaries for env macros
seonghobae Sep 19, 2026
8c83413
docs(browser-session): trace env macro Rust identifier boundary repair
seonghobae Sep 19, 2026
550d8bf
test(browser-session): expose Rust use XID boundary false positive
seonghobae Sep 19, 2026
1f323bc
fix(browser-session): use Rust lexical boundaries for use aliases
seonghobae Sep 19, 2026
a8998b0
docs(browser-session): trace Rust use XID boundary repair
seonghobae Sep 19, 2026
8b98d08
test(browser-session): expose compile-time env use boundary regression
seonghobae Sep 19, 2026
c06a36d
fix(browser-session): share Rust use/as identifier boundaries
seonghobae Sep 19, 2026
7478246
docs(browser-session): trace compile-time env alias boundary repair
seonghobae Sep 19, 2026
01aa661
docs(changelog): record Rust XID and empty host override repairs
seonghobae Sep 20, 2026
70cc9d8
fix(changelog): restore trailing newline after documentation repair
seonghobae Sep 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
234 changes: 210 additions & 24 deletions crates/originweave-browser-session/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ pub enum BrowserSessionError {
DuplicateBrowsingContext,
/// The port returned an isolation identity already known to this aggregate.
DuplicateDisposableIsolation,
/// A different lifecycle-port instance was supplied after this Browser Session bound its port.
LifecyclePortMismatch,
/// The requested context is not currently owned and active in this session.
ContextNotOwned,
/// The supplied authority belongs to another incarnation, isolation boundary, session, context, or epoch.
Expand Down Expand Up @@ -130,6 +132,33 @@ impl BrowserSessionIncarnation {
}
}

/// Stable non-zero identity for one live disposable-context lifecycle-port instance.
///
/// A reviewed adapter assigns this identity when the adapter instance is created and keeps it stable
/// for that instance's lifetime. Browser Session binds the first port identity it uses and rejects a
/// different identity before lifecycle I/O. This value identifies an adapter instance; it grants no
/// lifecycle authority by itself.
#[derive(Debug, Clone, Copy, PartialEq, Eq, PartialOrd, Ord, Hash)]
pub struct DisposableContextPortId(u64);

impl DisposableContextPortId {
/// Create a non-zero lifecycle-port instance identity.
#[must_use]
pub const fn new(value: u64) -> Option<Self> {
if value == 0 {
None
} else {
Some(Self(value))
}
}

/// Return the adapter-defined non-zero identity value.
#[must_use]
pub const fn value(self) -> u64 {
self.0
}
}

/// Adapter result for one newly created disposable browser context.
///
/// The isolation identity scopes the lifecycle boundary used for destruction; the browsing-context
Expand Down Expand Up @@ -178,36 +207,111 @@ pub enum BrowserSessionRecoveryEvidence {
UnprovenDestruction(DisposableContextHandle),
}

/// Opaque Browser Session-issued request for one disposable-context creation attempt.
///
/// There is deliberately no public constructor. Raw session, incarnation, or port identifiers are
/// insufficient to call the lifecycle port; Browser Session creates this request only after it has
/// validated aggregate state and bound the lifecycle-port instance.
#[derive(Debug)]
pub struct DisposableContextCreateRequest {
port_id: DisposableContextPortId,
browser_session: BrowserSessionId,
incarnation: BrowserSessionIncarnation,
}

impl DisposableContextCreateRequest {
/// Return the lifecycle-port instance this request is bound to.
#[must_use]
pub const fn port_id(&self) -> DisposableContextPortId {
self.port_id
}

/// Return the Browser Session transport identity for adapter addressability.
#[must_use]
pub const fn browser_session(&self) -> BrowserSessionId {
self.browser_session
}

/// Return the non-reused Browser Session incarnation for adapter lifecycle mapping.
#[must_use]
pub const fn incarnation(&self) -> BrowserSessionIncarnation {
self.incarnation
}
}

/// Opaque Browser Session-issued request for destruction of one exact owned disposable context.
///
/// There is deliberately no public constructor. The request is created only after Browser Session
/// validates the supplied presentation authority against current aggregate ownership and the bound
/// lifecycle-port instance.
#[derive(Debug)]
pub struct DisposableContextDestroyRequest {
port_id: DisposableContextPortId,
browser_session: BrowserSessionId,
incarnation: BrowserSessionIncarnation,
context: DisposableContextHandle,
}

impl DisposableContextDestroyRequest {
/// Return the lifecycle-port instance this request is bound to.
#[must_use]
pub const fn port_id(&self) -> DisposableContextPortId {
self.port_id
}

/// Return the Browser Session transport identity for adapter addressability.
#[must_use]
pub const fn browser_session(&self) -> BrowserSessionId {
self.browser_session
}

/// Return the non-reused Browser Session incarnation for adapter lifecycle mapping.
#[must_use]
pub const fn incarnation(&self) -> BrowserSessionIncarnation {
self.incarnation
}

/// Return the exact domain handle whose remote isolation boundary must be destroyed.
#[must_use]
pub const fn context(&self) -> &DisposableContextHandle {
&self.context
}
}

/// Port implemented by a reviewed browser adapter for disposable context lifecycle operations.
///
/// `incarnation` is domain-issued and must participate in the adapter's lifecycle mapping; ignoring it
/// would reintroduce sequential ABA aliasing. `create_disposable_context` must create a fresh isolation
/// boundary and context owned exclusively by the supplied Browser Session incarnation. For WebDriver
/// BiDi the isolation identity maps one-to-one to the user-context identifier returned by
/// `port_id` must be side-effect-free, stable for one live adapter instance, and distinct from other
/// simultaneously usable instances. Browser Session binds the first port id used by an aggregate and
/// rejects a different id before create or destroy I/O. This closes the raw port side door and prevents
/// a second adapter instance from becoming an alternate lifecycle target after the aggregate is bound.
///
/// The create/destroy requests have private construction paths. A caller that merely knows a browser
/// session id, incarnation, context id, isolation id, or port id cannot issue lifecycle I/O directly.
/// For WebDriver BiDi the isolation identity maps one-to-one to the user-context identifier returned by
/// `browser.createUserContext`.
///
/// [`DisposableContextCreateError::CreateFailedClean`] is allowed only when the adapter proves that no
/// disposable state was created. If a user-context identity is already known when later creation or
/// verification becomes uncertain, the adapter must return it inside
/// [`DisposableContextCreateError::CreateFailedUncertain`].
///
/// `destroy_disposable_context` must destroy the exact boundary carried by the supplied handle and
/// `destroy_disposable_context` must destroy the exact boundary carried by the supplied request and
/// return success only after destruction is proven. Reconstructing cleanup authority from raw driver
/// identifiers is forbidden, and a command acknowledgement alone is insufficient evidence.
pub trait DisposableContextPort {
/// Create one fresh disposable isolation boundary and browsing context for this incarnation.
/// Return this live adapter instance's stable lifecycle-port identity without browser I/O.
fn port_id(&self) -> DisposableContextPortId;

/// Create one fresh disposable isolation boundary and browsing context for this authorized request.
fn create_disposable_context(
&mut self,
browser_session: BrowserSessionId,
incarnation: BrowserSessionIncarnation,
request: &DisposableContextCreateRequest,
) -> Result<DisposableContextHandle, DisposableContextCreateError>;

/// Destroy the exact disposable isolation boundary represented by this handle and incarnation.
/// Destroy the exact disposable isolation boundary represented by this authorized request.
fn destroy_disposable_context(
&mut self,
browser_session: BrowserSessionId,
incarnation: BrowserSessionIncarnation,
context: &DisposableContextHandle,
request: &DisposableContextDestroyRequest,
) -> Result<(), DisposableContextDestroyError>;
}

Expand Down Expand Up @@ -291,6 +395,7 @@ pub struct BrowserSession {
state: BrowserSessionState,
transport_lost: bool,
next_epoch: u64,
lifecycle_port_id: Option<DisposableContextPortId>,
contexts: BTreeMap<BrowsingContextId, OwnedContextRecord>,
recovery_evidence: Vec<BrowserSessionRecoveryEvidence>,
}
Expand All @@ -315,6 +420,7 @@ impl BrowserSession {
state: BrowserSessionState::Active,
transport_lost: false,
next_epoch: 1,
lifecycle_port_id: None,
contexts: BTreeMap::new(),
recovery_evidence: Vec::new(),
})
Expand Down Expand Up @@ -356,8 +462,14 @@ impl BrowserSession {
port: &mut P,
) -> Result<PresentationMutationAuthority, BrowserSessionError> {
self.require_active()?;
let port_id = self.bind_lifecycle_port(port)?;
let epoch = reserve_epoch(&mut self.next_epoch)?;
let handle = match port.create_disposable_context(self.id, self.incarnation) {
let request = DisposableContextCreateRequest {
port_id,
browser_session: self.id,
incarnation: self.incarnation,
};
let handle = match port.create_disposable_context(&request) {
Ok(handle) => handle,
Err(DisposableContextCreateError::CreateFailedClean) => {
return Err(BrowserSessionError::ContextCreationFailed);
Expand Down Expand Up @@ -455,19 +567,27 @@ impl BrowserSession {
authority: &PresentationMutationAuthority,
port: &mut P,
) -> Result<(), BrowserSessionError> {
let port_id = self.require_bound_lifecycle_port(port)?;
let browser_session = self.id;
let incarnation = self.incarnation;
let record = self.context_for_authority_mut(authority)?;
let handle = record.handle.clone();
match port.destroy_disposable_context(browser_session, incarnation, &handle) {
let request = DisposableContextDestroyRequest {
port_id,
browser_session,
incarnation,
context: record.handle.clone(),
};
match port.destroy_disposable_context(&request) {
Ok(()) => {
record.state = OwnedContextState::Destroyed;
Ok(())
}
Err(DisposableContextDestroyError::DestroyFailed) => {
record.state = OwnedContextState::Uncertain;
self.recovery_evidence
.push(BrowserSessionRecoveryEvidence::UnprovenDestruction(handle));
.push(BrowserSessionRecoveryEvidence::UnprovenDestruction(
request.context,
));
self.enter_recovery_required();
Err(BrowserSessionError::ContextDestructionFailed)
}
Expand Down Expand Up @@ -504,6 +624,31 @@ impl BrowserSession {
Ok(())
}

fn bind_lifecycle_port<P: DisposableContextPort>(
&mut self,
port: &P,
) -> Result<DisposableContextPortId, BrowserSessionError> {
let supplied = port.port_id();
match self.lifecycle_port_id {
None => {
self.lifecycle_port_id = Some(supplied);
Ok(supplied)
}
Some(bound) if bound == supplied => Ok(bound),
Some(_) => Err(BrowserSessionError::LifecyclePortMismatch),
}
}

fn require_bound_lifecycle_port<P: DisposableContextPort>(
&self,
port: &P,
) -> Result<DisposableContextPortId, BrowserSessionError> {
match self.lifecycle_port_id {
Some(bound) if bound == port.port_id() => Ok(bound),
_ => Err(BrowserSessionError::LifecyclePortMismatch),
}
}

fn require_active(&self) -> Result<(), BrowserSessionError> {
if self.state == BrowserSessionState::Active {
Ok(())
Expand Down Expand Up @@ -587,6 +732,7 @@ mod tests {

#[derive(Debug)]
struct TestPort {
port_id: DisposableContextPortId,
next_handle: DisposableContextHandle,
create_error: Option<DisposableContextCreateError>,
fail_destroy: bool,
Expand All @@ -599,7 +745,12 @@ mod tests {

impl TestPort {
fn new(context: u64, isolation: &str) -> Self {
Self::with_port_id(context, isolation, 1)
}

fn with_port_id(context: u64, isolation: &str, port_id: u64) -> Self {
Self {
port_id: DisposableContextPortId::new(port_id).expect("valid port id"),
next_handle: DisposableContextHandle::new(
isolation_id(isolation),
context_id(context),
Expand All @@ -616,13 +767,17 @@ mod tests {
}

impl DisposableContextPort for TestPort {
fn port_id(&self) -> DisposableContextPortId {
self.port_id
}

fn create_disposable_context(
&mut self,
_browser_session: BrowserSessionId,
incarnation: BrowserSessionIncarnation,
request: &DisposableContextCreateRequest,
) -> Result<DisposableContextHandle, DisposableContextCreateError> {
assert_eq!(request.port_id(), self.port_id);
self.create_calls += 1;
self.create_incarnations.push(incarnation);
self.create_incarnations.push(request.incarnation());
match self.create_error.clone() {
Some(error) => Err(error),
None => Ok(self.next_handle.clone()),
Expand All @@ -631,13 +786,13 @@ mod tests {

fn destroy_disposable_context(
&mut self,
_browser_session: BrowserSessionId,
incarnation: BrowserSessionIncarnation,
context: &DisposableContextHandle,
request: &DisposableContextDestroyRequest,
) -> Result<(), DisposableContextDestroyError> {
assert_eq!(request.port_id(), self.port_id);
self.destroy_calls += 1;
self.destroy_incarnations.push(incarnation);
self.destroyed_isolations.push(context.isolation.clone());
self.destroy_incarnations.push(request.incarnation());
self.destroyed_isolations
.push(request.context().isolation.clone());
if self.fail_destroy {
Err(DisposableContextDestroyError::DestroyFailed)
} else {
Expand Down Expand Up @@ -685,6 +840,11 @@ mod tests {
let handle = DisposableContextHandle::new(valid.clone(), context_id(10));
assert_eq!(handle.isolation(), &valid);
assert_eq!(handle.browsing_context(), context_id(10));
assert_eq!(DisposableContextPortId::new(0), None);
assert_eq!(
DisposableContextPortId::new(17).expect("valid port id").value(),
17
);
}

#[test]
Expand Down Expand Up @@ -798,6 +958,32 @@ mod tests {
);
}

#[test]
fn lifecycle_port_binding_rejects_other_adapter_before_io() {
let mut session = session(32);
let mut first_port = TestPort::with_port_id(320, "isolation-320", 11);
let authority = session
.create_disposable_context(&mut first_port)
.expect("first lifecycle port is bound");

let mut other_port = TestPort::with_port_id(321, "isolation-321", 12);
assert_eq!(
session.create_disposable_context(&mut other_port),
Err(BrowserSessionError::LifecyclePortMismatch)
);
assert_eq!(other_port.create_calls, 0);
assert_eq!(
session.destroy_disposable_context(&authority, &mut other_port),
Err(BrowserSessionError::LifecyclePortMismatch)
);
assert_eq!(other_port.destroy_calls, 0);

session
.destroy_disposable_context(&authority, &mut first_port)
.expect("bound lifecycle port remains authorized");
assert_eq!(first_port.destroy_calls, 1);
}

#[test]
fn epoch_exhaustion_prevents_creation_io() {
let mut exhausted_session = session(4);
Expand Down
Loading
Loading