Skip to content

feat(network): transport node-bound WebDriver BiDi text input - #267

Draft
seonghobae wants to merge 18 commits into
feat/webdriver-bidi-node-type-textfrom
feat/webdriver-bidi-node-type-text-transport
Draft

feat(network): transport node-bound WebDriver BiDi text input#267
seonghobae wants to merge 18 commits into
feat/webdriver-bidi-node-type-textfrom
feat/webdriver-bidi-node-type-text-transport

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Pointer safeguards adopted — 2026-09-07 00:33 UTC

Published head ebd507ae56c3064e3cae5566502f539c20618a8f adopts live #266 e3885f69df2cf3899184209efdee5b11bba1bd86 through ordinary merge 7e4bd76d, preserving both contributor histories. Actual RED 4e020e16 failed all three real-socket regressions before adoption: foreign-session click dispatch and replacement success/error replies consuming the original request. All 23 focused pointer, navigation and text-send tests now pass. The entire core crate, text sender, exports and all ten text-send tests are unchanged from 3346d8ec.

Full exact-head Rust 1.97.1 formatting, locked workspace checks/tests, five compile-fail doctests, strict Clippy and warning-denied rustdoc pass, alongside 145 Python contracts, compileall, healthy CodeGraph and diff checks. Production coverage is 1318/1318 functions, 13852/13852 lines, 17610/17610 regions and 1456/1456 branches. Local coverage-pointer-ebd507ae.json SHA256 8bd32ad83ba5f9ef65bad8a3503f5e6cff38335b8526bff9f974bd6ee7fabceb; the pinned nightly branch-instrumentation warning remains explicit. Independent read-only review found no actionable issues; it is not formal approval.

CI 34070121583, Rust job 101585791003 and coverage job 101585790871, are queued, not successful. Actual isolated-Edge screenshots of the published PR and exact-commit dossier show the matching head/base, Draft state and readable evidence, with no observed clipping or overlap at 1440×1100. The original browser-control connection failed; the installed browser fallback completed without changing authentication or permissions. This verifies GitHub presentation only, not OriginWeave browser-runtime acceptance.

Keep Draft. #268 owns text-response admission; field-value post-conditions, browser authentication, policy, protected-main integration and release evidence remain separate. No force rewrite, gate, workflow, approval, merge or release change.

Historical sender and predecessor evidence

Current sender-provenance prerequisite — 2026-09-06 14:46 UTC

Exact head 3346d8ecc72932b98ec495d9cc52d6e5727c3064 retains the original connection of each pending text-entry request using the existing private-generation registration API before I/O. Parent remains #266 eb6c236ff2f4a58b807a2f2c914bd1ddb6079fb3. Session/current-node validation, deadlines, malformed-frame retirement and uncertain-write retention are preserved.

Actual child #268 RED 4632f2df accepted a response on a same-session replacement socket. Sealed consumer d6889c80 exposed the sender's missing generation; ordinary integration e1188c86 of this owner fix makes the real replacement-socket success/error rejection and original recovery test pass. Child tests are local integration evidence until their publication is verified.

Full exact-head local Rust1.97.1 fmt/check/workspace tests/strict Clippy/warning-denied rustdoc, 145 Python contracts, compileall/CodeGraph/diff checks pass. Production coverage: 1317/1317 functions,13835/13835 lines,17598/17598 regions,1456/1456 branches. Local coverage-sender-provenance.json SHA256 8d7a3687557d067ee99fd512936077c0c9662d40d9d6544232bb5a377dc88e23. Hosted checks are not claimed passing. Keep Draft; this prerequisite does not change generic response consumers, prove field values, authorize actions or authenticate a browser. No merge, approval, gate, workflow or release change.

Historical predecessor evidence

Current parent integration and security repair — 2026-09-06

Exact published head 4435ce5f561ca069c1844a1a5bd9b603505e25f7 adopts live #266 parent eb6c236ff2f4a58b807a2f2c914bd1ddb6079fb3 via ordinary merge d903cf6b. Original child 46a05d7f and parent histories are preserved. Keep Draft; no protected-main or browser-outcome acceptance is claimed.

Test-first repairs

  • 2b960002: actual socket regression failed because a zero frame deadline retained one unsent command. The existing canonical validator now runs before registration.
  • Parent adoption exposed removed generic correlation. Text uses its distinct TypeText family and the existing sealed command-write lane; no duplicate transport is introduced.
  • e2b49e68: reused-mask no-write preflight wrongly retained correlation. Only malformed-frame preflight retires the exact typed id; an actual ambiguous socket failure retains it.
  • Independent review found a pre-existing cross-session dispatch gap. 10131eb7 reproduced it; c3dc8e76 uses the parent's read-only registry session mapping before correlation/action bytes. The regression requires exact mismatch, zero outstanding commands and wire silence. Valid fixtures now align session identities. Follow-up independent review found no further source findings; it is not counted approval.

Exact local verification

Final-head Rust 1.97.1 fmt, locked all-target check, full workspace/all-feature tests and doctests, strict Clippy and rustdoc pass. All 145 Python contracts, compileall, CodeGraph and diff checks pass. Ten focused text-transport tests pass. Pinned nightly 2026-08-01 exact owned production coverage passes: 1317/1317 functions, 13832/13832 lines, 17596/17596 regions, 1456/1456 branches. Coverage SHA-256 065e535fd49c34699b35d53b4cc6b09f22b3dff506f07eb5549c21b73074bdc8; unstable branch-instrumentation warning remains explicit.

Current CI 34038399969 jobs Rust 101500584783 and coverage 101500584823 are queued, not successful. Historical CI below is not current acceptance. #268 already owns typed response admission; authentication, policy approval, post-condition evidence and real browser integration remain separate.

Visual inspection

Actual Edge screenshots of the published PR body and Checks page show readable wrapping, no observed clipping or overlap, Draft state and exact 4435ce5 revision. Rendered check links match CI 34038399969 and jobs 101500584783/101500584823. This verifies GitHub presentation only, not OriginWeave browser-runtime acceptance.

Historical pre-adoption evidence

Partial implementation of #28, stacked directly on PR #266 branch feat/webdriver-bidi-node-type-text exact head cc9980c095577e968014908aeb7c9fda06e516f3.

Buyer-visible boundary

This slice transports the existing node-bound non-secret WebDriverBiDiTypeTextCommand across the reviewed WebDriver BiDi/RFC 6455 boundary. The public send API consumes an exact WebDriver BiDi TypedInput protocol-use proof, reconstructs the command from the supplied text and live admitted-node authority immediately before dispatch, registers the command identifier before the first possible remote side effect, then emits one bounded masked WebSocket text frame.

Wrong protocol family or capability, invalid/over-budget text, stale document authority, external-context or node-identifier mismatch, and duplicate correlation all fail before action-frame I/O. Once the command identifier is registered, a frame-write failure deliberately leaves it outstanding because partial or complete remote execution is ambiguous; the identifier is not silently reused. The transport does not retry, reconnect, select an alternate destination, grant browser/policy/secret authority, infer post-condition success, or retain the typed text in its error variants.

Test-first evidence

Exact RED head 9128711b714e55fc17ace673a183f1738a03ad3c added a realistic loopback TCP → RFC 6455 integration regression requiring the public network crate to send the exact authority-bound input.performActions text command and retain its command id as outstanding for later correlated acknowledgement. CI run 33453235645, Rust contracts job 99687573487, failed because the production send_webdriver_bidi_type_text boundary did not yet exist. That failure is retained as RED lineage only.

The implementation then added focused hostile/failure regressions for protocol/capability mismatch, invalid text with privacy-safe diagnostics, duplicate correlation, invalid frame deadline after registration, and a stale node after document advancement. A first GREEN candidate exposed only a canonical rustfmt defect; the exact generated formatter diagnostic was applied without semantic changes.

Exact-current evidence

Current exact head is 46a05d7f8a1219803cafb38fc33deb263a1c14cc against independently resolved live base cc9980c095577e968014908aeb7c9fda06e516f3. GitHub reports the PR open, Draft, and mergeable.

Exact native CI run 33453789654 completed success on this unchanged head:

  • Rust contracts job 99689293802: repository contracts, canonical formatting, workspace check, full tests, strict Clippy, and API documentation/rustdoc success;
  • Production coverage job 99689293545: exact owned-production enforcement success with functions 1271/1271, lines 13081/13081, regions 16801/16801, and branches 1424/1424.

Exact coverage artifact 9780738538 (exact-coverage-46a05d7f8a1219803cafb38fc33deb263a1c14cc) has digest sha256:19938f9d5568aac5393dfbac3aa01ad26bf36709328baceb7c3546d36e05260e.

The exact-head check inventory currently contains Rust contracts and Production coverage only; no absent central or browser-specific workflow is promoted to passing evidence. Fresh formal reviews and review threads are empty, so no independent approval is claimed or inferred. No predecessor, skipped, queued, cancelled, stale, synthetic, model-only, author-only, or status-only evidence is promoted to the exact current head.

Stack / authority boundary

Keep Draft while #266 and its ancestors remain Draft. Protocol acknowledgement remains separate from observed action success; correlated response admission and buyer-visible post-condition evidence are deliberately outside this transport slice and remain subsequent #28 work. Protected-main AGENTS.md and live GitHub governance remain authoritative. This scheduled writer does not merge, self-approve, force-push, destructively rebase, alter workflows/rulesets/secrets, weaken checks, tag, release, or publish.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Bounded text-transport writer RELEASED — 2026-09-06 14:14 UTC

Root task 01a06c0f-b427-7830-b654-9addcdfe7aff releases #267 after ordinary publication and readback of 4435ce5 on live parent eb6c236. Both ancestries preserved. Actual REDs 2b96000 (invalid deadline), e2b49e6 (no-write preflight retention), 10131eb (foreign session) preceded fixes. Ten focused tests, final-head full Rust1.97.1 gates, 145 Python contracts, compileall/CodeGraph/diff and exact 100% production coverage 1317/13832/17596/1456 pass. Coverage SHA256 065e535fd49c34699b35d53b4cc6b09f22b3dff506f07eb5549c21b73074bdc8. Independent review P1 fixed and rechecked; no further source finding, not counted approval.

Actual Edge screenshots verify published PR body and Checks exact head, Draft state, readable layout and matching queued CI34038399969 jobs101500584783/101500584823. Hosted success and product-browser acceptance are not claimed. Source writer is released; no workflow, gate, approval, merge or release mutation. Next queue: #238 newly reported latest-root/lineage historical-scope findings, then existing #268 TypeText response consumer adoption without generic correlation restoration.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>

# Conflicts:
#	crates/originweave-network/src/lib.rs
Reuse the canonical frame timeout validator; preserve ambiguous write retention.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
…ejection

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>

seonghobae commented Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

Text sender provenance writer RELEASED — 2026-09-06 14:47 UTC

Published/read back3346d8ecc72932b98ec495d9cc52d6e5727c3064 on eb6c236. Complete Rust gates,145 Python contracts,CodeGraph/compileall/diff and100% coverage1317/13835/17598/1456 pass. Artifact SHA2568d7a3687557d067ee99fd512936077c0c9662d40d9d6544232bb5a377dc88e23. Independent combined sender/consumer review found no actionable issue, not approval. Actual Edge screenshot verifies current head/base, Draft state and readable published evidence with no visible clipping/overlap. CI34040202356 Rust101505448182/coverage101505448009 queued. Parent has no active process or source writer; child268 remains the sole active slice. No merge/gate/workflow/approval/release change.

Commit-Message-Assisted-by: Codex (via Codex)
Signed-off-by: Seongho Bae <me@seonghobae.me>

seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Writer lease RELEASED — 2026-09-07 00:36 UTC. Root task 01a06c0f-b427-7830-b654-9addcdfe7aff published and read back #267 ebd507a on parent266 e3885f6. Actual RED4e020e16 reproduced 0/3 pointer failures before ordinary adoption7e4bd76d. All23 focused tests, complete Rust1.97.1 gates,145 Python contracts,compileall,diff and healthy CodeGraph pass; production coverage1318/13852/17610/1456 each100%, SHA2568bd32ad83ba5f9ef65bad8a3503f5e6cff38335b8526bff9f974bd6ee7fabceb. Independent read-only review found no issues, not formal approval. Actual isolated Edge screenshots of published PR and exact-commit dossier verify matching hashes, Draft state and readable layout without observed overlap/clipping; CUA app-server failure/timeouts were bypassed with the installed browser runtime, no permissions/authentication changes. GitHub presentation is not product-browser acceptance. CI34070121583 jobs101585791003/101585790871 remain queued. No active source writer/process; no force, workflow, gate, approval, protected merge or release mutation. Next safe queue: dated #238 published265–267 baseline refresh, then #268 parent adoption preserving its text-response consumer.

Copy link
Copy Markdown
Contributor Author

Exact-head hosted evidence checkpoint — evidence-only PR-state lease acquired after fresh public coordination confirmed writer 5563277731 RELEASED and no later unreleased #267 lease; released in this same checkpoint with no source/docs/ref mutation.

Exact current head ebd507ae56c3064e3cae5566502f539c20618a8f, direct parent #266 e3885f69df2cf3899184209efdee5b11bba1bd86, Draft. CI 34070121583, previously queued, has now actually executed and completed terminal success on this unchanged head. Rust contracts 101585791003 passed repository contracts, rustfmt, workspace check, full tests, strict Clippy and API docs. Production coverage 101585790871 obtained runner 1001729219, checked out this exact head, completed measurement and exact enforcement successfully. The prior runner-admission observation is therefore historical for this leaf rather than a current source blocker.

This does not transfer evidence to #268 or establish product-browser/post-condition acceptance, formal approval, protected-main integration, tag or release. Existing actual Edge screenshots remain GitHub-presentation evidence only. No workflow/ruleset/secret/gate change, force update, source write, protected merge, tag or release occurred. No #267 writer remains held after this checkpoint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant