Buyer-visible gap
originweave-fingerprint owns pure presentation identity. OriginWeave still needs browser-domain proof that an admitted profile is actually applied before page script, observed from the same version-pinned Chromium context, survives required failure cases, and is safely restored or destroyed. Protocol acknowledgement alone is not success.
This remains OriginWeave browser-runtime authority. MCP/driver transports, LLMs, Keyverse, Wardnet, EgressWeave, and contextual-orchestrator must not become deterministic browser-policy or presentation-truth owners.
Standards boundary — observed 2026-09-10
The canonical W3C Technical Report page identifies WebDriver BiDi Working Draft, 9 September 2026, immutable dated TR https://www.w3.org/TR/2026/WD-webdriver-bidi-20260909/.
The OriginWeave standard-BiDi capability map is still runtime-qualified against 3 September 2026, not silently repinned to the newest publication. PR #229 records this distinction: publication freshness and runtime compatibility are separate evidence. Advancing the supported revision requires its own schema/semantics/conformance and pinned-Chromium requalification.
The current standard provides viewport/DPR, screen-settings, locale, media-feature, timezone and user-agent emulation surfaces plus user-context lifecycle primitives. It still does not by itself prove OriginWeave's complete canonical Screen including color depth, ordered Languages, HardwareConcurrency, or the full Chromium platform/UA-CH presentation boundary. Partial capability must remain fail closed.
Invariants
originweave-fingerprint remains the pure profile/value owner; browser adapters depend inward on it.
- Capability claims are explicit per supported browser/protocol revision. Missing or partial required surfaces cannot be completed with ambient host values.
- Prefer standard WebDriver BiDi where it completely represents a canonical surface. Chromium-specific CDP is allowed only behind a narrow versioned adapter for remaining Chromium surfaces; no generic DevTools or JavaScript pass-through.
- Apply before the target page script/navigation epoch being evidenced. Navigation or renderer replacement invalidates evidence unless the lifecycle explicitly re-establishes it.
- ACK is not evidence. Read the page-visible post-condition from the exact context and compare with the admitted profile.
- Apply/cleanup authority is symmetric. Reusable contexts must not install state that generic cleanup cannot safely restore. If media or screen-area mutation is required, snapshot/restore complete prior state or use a Browser Session-owned disposable context/profile and prove destruction.
- A raw browsing-context identifier is addressability, not mutation authority. Viewport/DPR, timezone, and screen-area Set/Reset may be exposed only with an owner-issued lifecycle witness; generic cleanup must not clear another owner's predecessor override.
- Aggregate incarnation is part of mutation authority. Reusing the same externally supplied
BrowserSessionId, browsing-context ID, and local epoch across two BrowserSession aggregates must never make one aggregate accept the other's authority or perform port I/O for it.
- Unsupported revision/mode, partial application, command error, observed mismatch, renderer crash or cleanup failure is non-passing.
- Presentation consistency is privacy/compatibility behavior, not authorization to bypass CAPTCHA, consent or access control.
Current dependency / delivery state
Protected main remains 87c4daa1830bac5a5228b6036752ad5633232085.
PR #293 is already merged into the #229 parent branch. PR #310 then inherited #311's screen-area ownership-witness repair, produced exact-head repository GREEN at af59acb08af802bba8d51bc23bd762c08f8ce481 in CI 34424716839, and was normally merged into #229 at cfb58600a2253b6f1751f5252f4aabfbec6e9cc1. Child GREEN remains lineage evidence only.
A separate #229 source writer has since advanced that parent by ordinary commits to exact 7ec83c1be1a8e8724d37c2d6ebbdb215b1b10e23, still open / Ready / mergeable directly on protected main. Test-first f8966d084bdb63901a77903ac81f7d6938f09957 requires reusable viewport/DPR/timezone apply and cleanup to accept a non-caller-mintable WebDriverBidiPresentationOwnership rather than a raw WebDriverBidiBrowsingContext. Minimal production ff15612e0187683a7d2f738c0b7cfe711549ba2b carries that witness through Set/Reset command intent and documents that nullable reset removes an override or returns to implementation default rather than restoring an unrelated predecessor override. Current 7ec83c1be1a8e8724d37c2d6ebbdb215b1b10e23 exports the opaque witness from originweave-bidi without adding a public mint path. CodeRabbit review finding 3974750524 is marked addressed/resolved by this lineage. The separate source-writer lease remains active; repository GREEN is not merge authority or browser acceptance.
The inherited screen-area boundary remains narrower and separate. WebDriverBidiScreenAreaOwnership is non-caller-mintable; screen-area Set/Reset vocabulary requires that witness, and there is no public screen-area planner until the Browser Session bounded context adds a reviewed ownership/disposable-lifecycle mint transition and consuming path together. Complete PresentationSurface::Screen remains fail closed while available-screen geometry and color depth are uncontrolled. The general presentation witness likewise may be minted only by a Browser Session lifecycle that proves an exclusive/disposable context or equivalent predecessor-state safety; a remote-issued context identifier alone is not authority.
Issue #312 now owns that Browser Session lifecycle gap. Stacked PR #313 is open / Ready / mergeable on #229 base 7ec83c1...; latest inspected head 797157a02547e7054e6290090d148483cc7ad560 introduces the originweave-browser-session aggregate and disposable-context port. It is not yet admissible: CodeRabbit blocking review 5613071726 proves that public BrowserSession::start(BrowserSessionId) plus per-aggregate epoch 1 can alias across two aggregates when the adapter returns the same browsing-context ID. The current authority tuple contains only (browser_session, browsing_context, context_epoch), so another aggregate with the same tuple can pass validation and reach destroy I/O. The only commit after the reviewed 9146d62... head changes ARCHITECTURE.md; the production alias remains at 797157a.... Exact-current reviewer handoff 5613165179 requires a hostile two-aggregate RED and a non-aliased owner-issued lease/incarnation (or equivalent domain proof) checked before port I/O. Do not merge #313 or expose its authority mint path until that RED is repaired and exact-head GREEN is independently observed.
The exact #229 workflow generation is now terminal rather than queued. Native CI 34428243419 SUCCESS, Security Scan 34428243446 SUCCESS, SAST Semgrep 34428243481 SUCCESS, and Strix 34428243671 SUCCESS. Required CodeQL PR 34428243635 FAILURE remains a central exact-job dispatch/wake ordering problem rather than an OriginWeave source failure. Required OpenCode 34428243675 FAILURE admits exact head and requests current-head execution, then fails closed because no current-head verdict is available. Required Noema 34428243682 FAILURE admits exact head, validates trusted source/credential/head and successfully provisions the contextual-orchestrator sidecar, then fails at Prepare Noema model verdict; publication is skipped and failure evidence is preserved. No leaf provider/model/group pin, paid fallback, retry heuristic or gate weakening is authorized by those failures.
The central model-review repair remains owned by contextual-orchestrator #1106 and .github #2042: CO must ship immutable free-pool admission/routing capability, then the central consumer removes its temporary provider/credential probing and TTC heuristics. OriginWeave consumes only the released gateway contract with orchestrator/free; mutable owner PRs are not dependencies.
The central CodeQL repair lineage is likewise a canonical .github concern. The current exact #229 canary again shows the required compatibility jobs reading the current-head verdict before the later dispatch job succeeds. Until the protected handler/wake path is integrated and a fresh OriginWeave generation settles terminal GREEN, #229 must not add a leaf CodeQL shim, mutable-PR pin, synthetic status, no-op retrigger or gate weakening.
The real browser evidence lane remains PR #299 exact a88d2affaac3b7519141218ae3a26ed625e31ace, open / Ready / mergeable on base f0037c69da3ad53277dbab76e9b9616e806bf35c. Repository CI 34387423912 is GREEN, including exact production coverage. Real Manifest V3 / Chrome for Testing run 34387423894 is RED before navigation. Artifact 10118270815, digest sha256:c0af559afd05205f3cb7066d4e34cb3d9b0585a8f79bdc7fa0520237a101f6ac, records Chrome/ChromeDriver 150.0.7871.129 (r1639810) with Agent Task 0/3. Every trial is AgentTaskSessionStartError with bounded failure_cause_type=WebDriverSessionNotCreatedError; there are no browser passes or presentation surfaces. Therefore presentation apply, page-observed target, native interaction/outcome, reset, original-baseline re-observation and full session/profile cleanup are still unproven.
Issue #212 owns current-generation Chromium workflow/sandbox-helper mechanics. PR #148 owns bounded ChromeDriver startup/process diagnosis. #292/#299 consume those authorities; they must not copy or weaken them. The current #148 diagnostic branch can still classify the real hosted failure only as session_not_created / startup_reason=unknown, so #292 must not promote helper/AppArmor/sandbox causality beyond the evidence.
Acceptance order
- RED authority: two logical Browser Session aggregates that reuse external session/context identifiers must not share mutation or destruction authority; foreign-incarnation authority must be rejected before any adapter I/O.
- RED: pinned Chromium ambient baseline is observably distinct from a deliberately selected valid target, or the adapter is demonstrably absent/partial.
- RED: any missing/partial required canonical surface prevents a complete-profile witness.
- RED lifecycle: reusable presentation state cannot survive generic cleanup safely; alternatively prove Browser Session-owned predecessor restoration or disposable-context/profile destruction.
- Minimal implementation: typed, version-pinned BiDi/CDP application and cleanup only for the admitted profile/lifecycle.
- GREEN: pinned Chromium observes matching screen dimensions/color depth, viewport, DPR, hardware concurrency, timezone, platform, ordered languages/UA-CH boundary and reduced motion before presentation success is recorded.
- GREEN interaction: native clear/type/click is followed by independent browser-observed input state, accepted outcome and URL-stability evidence; command acknowledgement alone is non-passing.
- GREEN cleanup: exact reusable context observes restored pre-state, or the owned disposable context/profile is proven destroyed. ACK is insufficient.
- Exercise navigation, renderer/process failure, partial-command failure, unsupported capability, mismatch and cleanup failure while preserving owned production function/line/region/branch and rustdoc/test coverage requirements.
- Update ARCHITECTURE/PRD/TRD/ADR/doctoring/traceability/product-gap documents only to exercised behavior.
Keep this issue open until the exact pinned Chromium path proves the complete causal sequence and reaches protected main through normal review and required workflows. No self-approval, force push, destructive rebase, bypass, gate weakening, workflow/ruleset/secret mutation, tag or release is part of this issue.
References
World Wide Web Consortium. (2026, September 9). WebDriver BiDi (W3C Working Draft). https://www.w3.org/TR/2026/WD-webdriver-bidi-20260909/
World Wide Web Consortium. (2026, September 3). WebDriver BiDi (W3C Working Draft; current OriginWeave runtime-qualified pin). https://www.w3.org/TR/2026/WD-webdriver-bidi-20260903/
World Wide Web Consortium. (2026). WebDriver BiDi (Editor’s Draft). https://w3c.github.io/webdriver-bidi/
Chromium Project. (2026). Chrome DevTools Protocol: Emulation domain (tip-of-tree; compatibility not guaranteed across revisions). https://chromedevtools.github.io/devtools-protocol/tot/Emulation/
Buyer-visible gap
originweave-fingerprintowns pure presentation identity. OriginWeave still needs browser-domain proof that an admitted profile is actually applied before page script, observed from the same version-pinned Chromium context, survives required failure cases, and is safely restored or destroyed. Protocol acknowledgement alone is not success.This remains OriginWeave browser-runtime authority. MCP/driver transports, LLMs, Keyverse, Wardnet, EgressWeave, and contextual-orchestrator must not become deterministic browser-policy or presentation-truth owners.
Standards boundary — observed 2026-09-10
The canonical W3C Technical Report page identifies WebDriver BiDi Working Draft, 9 September 2026, immutable dated TR
https://www.w3.org/TR/2026/WD-webdriver-bidi-20260909/.The OriginWeave standard-BiDi capability map is still runtime-qualified against 3 September 2026, not silently repinned to the newest publication. PR #229 records this distinction: publication freshness and runtime compatibility are separate evidence. Advancing the supported revision requires its own schema/semantics/conformance and pinned-Chromium requalification.
The current standard provides viewport/DPR, screen-settings, locale, media-feature, timezone and user-agent emulation surfaces plus user-context lifecycle primitives. It still does not by itself prove OriginWeave's complete canonical
Screenincluding color depth, orderedLanguages,HardwareConcurrency, or the full Chromium platform/UA-CH presentation boundary. Partial capability must remain fail closed.Invariants
originweave-fingerprintremains the pure profile/value owner; browser adapters depend inward on it.BrowserSessionId, browsing-context ID, and local epoch across twoBrowserSessionaggregates must never make one aggregate accept the other's authority or perform port I/O for it.Current dependency / delivery state
Protected
mainremains87c4daa1830bac5a5228b6036752ad5633232085.PR #293 is already merged into the #229 parent branch. PR #310 then inherited #311's screen-area ownership-witness repair, produced exact-head repository GREEN at
af59acb08af802bba8d51bc23bd762c08f8ce481in CI34424716839, and was normally merged into #229 atcfb58600a2253b6f1751f5252f4aabfbec6e9cc1. Child GREEN remains lineage evidence only.A separate #229 source writer has since advanced that parent by ordinary commits to exact
7ec83c1be1a8e8724d37c2d6ebbdb215b1b10e23, still open / Ready / mergeable directly on protectedmain. Test-firstf8966d084bdb63901a77903ac81f7d6938f09957requires reusable viewport/DPR/timezone apply and cleanup to accept a non-caller-mintableWebDriverBidiPresentationOwnershiprather than a rawWebDriverBidiBrowsingContext. Minimal productionff15612e0187683a7d2f738c0b7cfe711549ba2bcarries that witness through Set/Reset command intent and documents that nullable reset removes an override or returns to implementation default rather than restoring an unrelated predecessor override. Current7ec83c1be1a8e8724d37c2d6ebbdb215b1b10e23exports the opaque witness fromoriginweave-bidiwithout adding a public mint path. CodeRabbit review finding3974750524is marked addressed/resolved by this lineage. The separate source-writer lease remains active; repository GREEN is not merge authority or browser acceptance.The inherited screen-area boundary remains narrower and separate.
WebDriverBidiScreenAreaOwnershipis non-caller-mintable; screen-area Set/Reset vocabulary requires that witness, and there is no public screen-area planner until the Browser Session bounded context adds a reviewed ownership/disposable-lifecycle mint transition and consuming path together. CompletePresentationSurface::Screenremains fail closed while available-screen geometry and color depth are uncontrolled. The general presentation witness likewise may be minted only by a Browser Session lifecycle that proves an exclusive/disposable context or equivalent predecessor-state safety; a remote-issued context identifier alone is not authority.Issue #312 now owns that Browser Session lifecycle gap. Stacked PR #313 is open / Ready / mergeable on #229 base
7ec83c1...; latest inspected head797157a02547e7054e6290090d148483cc7ad560introduces theoriginweave-browser-sessionaggregate and disposable-context port. It is not yet admissible: CodeRabbit blocking review5613071726proves that publicBrowserSession::start(BrowserSessionId)plus per-aggregate epoch1can alias across two aggregates when the adapter returns the same browsing-context ID. The current authority tuple contains only(browser_session, browsing_context, context_epoch), so another aggregate with the same tuple can pass validation and reach destroy I/O. The only commit after the reviewed9146d62...head changesARCHITECTURE.md; the production alias remains at797157a.... Exact-current reviewer handoff5613165179requires a hostile two-aggregate RED and a non-aliased owner-issued lease/incarnation (or equivalent domain proof) checked before port I/O. Do not merge #313 or expose its authority mint path until that RED is repaired and exact-head GREEN is independently observed.The exact #229 workflow generation is now terminal rather than queued. Native CI
34428243419SUCCESS, Security Scan34428243446SUCCESS, SAST Semgrep34428243481SUCCESS, and Strix34428243671SUCCESS. Required CodeQL PR34428243635FAILURE remains a central exact-job dispatch/wake ordering problem rather than an OriginWeave source failure. Required OpenCode34428243675FAILURE admits exact head and requests current-head execution, then fails closed because no current-head verdict is available. Required Noema34428243682FAILURE admits exact head, validates trusted source/credential/head and successfully provisions the contextual-orchestrator sidecar, then fails atPrepare Noema model verdict; publication is skipped and failure evidence is preserved. No leaf provider/model/group pin, paid fallback, retry heuristic or gate weakening is authorized by those failures.The central model-review repair remains owned by contextual-orchestrator #1106 and
.github#2042: CO must ship immutable free-pool admission/routing capability, then the central consumer removes its temporary provider/credential probing and TTC heuristics. OriginWeave consumes only the released gateway contract withorchestrator/free; mutable owner PRs are not dependencies.The central CodeQL repair lineage is likewise a canonical
.githubconcern. The current exact #229 canary again shows the required compatibility jobs reading the current-head verdict before the later dispatch job succeeds. Until the protected handler/wake path is integrated and a fresh OriginWeave generation settles terminal GREEN, #229 must not add a leaf CodeQL shim, mutable-PR pin, synthetic status, no-op retrigger or gate weakening.The real browser evidence lane remains PR #299 exact
a88d2affaac3b7519141218ae3a26ed625e31ace, open / Ready / mergeable on basef0037c69da3ad53277dbab76e9b9616e806bf35c. Repository CI34387423912is GREEN, including exact production coverage. Real Manifest V3 / Chrome for Testing run34387423894is RED before navigation. Artifact10118270815, digestsha256:c0af559afd05205f3cb7066d4e34cb3d9b0585a8f79bdc7fa0520237a101f6ac, records Chrome/ChromeDriver150.0.7871.129(r1639810) with Agent Task 0/3. Every trial isAgentTaskSessionStartErrorwith boundedfailure_cause_type=WebDriverSessionNotCreatedError; there are no browser passes or presentation surfaces. Therefore presentation apply, page-observed target, native interaction/outcome, reset, original-baseline re-observation and full session/profile cleanup are still unproven.Issue #212 owns current-generation Chromium workflow/sandbox-helper mechanics. PR #148 owns bounded ChromeDriver startup/process diagnosis. #292/#299 consume those authorities; they must not copy or weaken them. The current #148 diagnostic branch can still classify the real hosted failure only as
session_not_created / startup_reason=unknown, so #292 must not promote helper/AppArmor/sandbox causality beyond the evidence.Acceptance order
Keep this issue open until the exact pinned Chromium path proves the complete causal sequence and reaches protected main through normal review and required workflows. No self-approval, force push, destructive rebase, bypass, gate weakening, workflow/ruleset/secret mutation, tag or release is part of this issue.
References
World Wide Web Consortium. (2026, September 9). WebDriver BiDi (W3C Working Draft). https://www.w3.org/TR/2026/WD-webdriver-bidi-20260909/
World Wide Web Consortium. (2026, September 3). WebDriver BiDi (W3C Working Draft; current OriginWeave runtime-qualified pin). https://www.w3.org/TR/2026/WD-webdriver-bidi-20260903/
World Wide Web Consortium. (2026). WebDriver BiDi (Editor’s Draft). https://w3c.github.io/webdriver-bidi/
Chromium Project. (2026). Chrome DevTools Protocol: Emulation domain (tip-of-tree; compatibility not guaranteed across revisions). https://chromedevtools.github.io/devtools-protocol/tot/Emulation/