Skip to content

feat: add privacy-preserving presentation identity kernel - #229

Open
seonghobae wants to merge 204 commits into
mainfrom
feat/privacy-presentation-identity
Open

feat: add privacy-preserving presentation identity kernel#229
seonghobae wants to merge 204 commits into
mainfrom
feat/privacy-presentation-identity

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Buyer-visible boundary

This PR owns the pure Rust presentation-identity kernel and its versioned standard-WebDriver-BiDi capability/planning boundary. It validates explicit browser-visible profiles and bounded presentation/fingerprint surfaces. The originweave-bidi slice plans typed presentation command intent; it does not itself send protocol commands or prove page-observed state.

This is active-PR evidence, not protected-main shipment. It does not inspect the host, patch Chromium, bypass access controls, treat command acknowledgement as success, or absorb #148/#212/#292/#299 browser-startup, sandbox, or real-browser acceptance authority.

Current lineage

Protected main is exact 87c4daa1830bac5a5228b6036752ad5633232085. Exact current head is cfb58600a2253b6f1751f5252f4aabfbec6e9cc1 on feat/privacy-presentation-identity.

No predecessor was simple-closed to reduce PR count, and no force push or destructive rebase was used for these integrations.

Standards and screen-area authority

The standards-freshness lineage keeps publication tracking separate from runtime qualification: the OriginWeave standard-BiDi adapter remains runtime-qualified against the immutable 3 September 2026 revision recorded in its source/contracts. A newer publication alone does not silently repin runtime behavior; advancing the runtime pin requires dedicated schema/semantics/conformance and pinned-Chromium requalification.

The inherited screen-area repair keeps the reusable profile-derived planner limited to viewport/DPR plus timezone. emulation.setScreenSettingsOverride remains a separately typed partial capability because one screenArea rectangle also controls page-visible available-screen geometry that the current presentation profile does not model, while color depth is also uncontrolled. Complete PresentationSurface::Screen therefore remains fail closed.

Screen-area Set/Reset command vocabulary now carries opaque WebDriverBidiScreenAreaOwnership. A raw browsing-context identifier is addressability, not mutation authority: no public screen-area planner exists until the Browser Session bounded context supplies a reviewed ownership/disposable-lifecycle mint transition and consuming path together. This prevents generic cleanup from clearing another owner's predecessor override. Proposed ADR 0113 and focused doctoring/traceability are inherited with that boundary.

Current exact-head verification

The current parent head cfb58600a2253b6f1751f5252f4aabfbec6e9cc1 has a fresh post-integration workflow generation; no earlier GREEN or RED is transferred.

At the latest read:

  • CI 34426254120: queued.
  • Security Scan 34426254122: queued.
  • SAST Semgrep 34426254144: queued.
  • Required CodeQL PR 34426254109: queued.

The predecessor #229 exact 6f95808ce1166254c6c5dea33a1015d9405ee03f had native CI/Security/Semgrep GREEN but required CodeQL terminal RED in the canonical exact-job wake path. That result is historical after this parent advance. Fresh central-owner search now shows the later .github wake lineage has moved beyond #2040: #2051 centralizes wake responsibility after the complete scan matrix, and Ready successor #2056 exact 69ae472562c93cc17674af5e2085a58947d3fab8 additionally requires the authenticated job binding to equal the run's complete failed-job set before one rerun-failed-jobs call. These are proposed central-owner repairs, not immutable consumer dependencies. The leaf must not pin either mutable PR, add a CodeQL shim, synthesize status, make an empty/no-op retrigger, copy workflows, or weaken the gate. A protected central integration/release and a new OriginWeave exact-head generation remain required.

Keep this PR unmerged until the current exact head passes repository checks, required central workflows, review-thread requirements, and a qualifying independent approval under the live protected-main ruleset.

Browser acceptance remains open

The real-browser evidence lane remains #299. Its previously verified repository head is GREEN, but pinned Chrome/ChromeDriver 150.0.7871.129 Agent Task evidence remains 0/3 pre-navigation RED with bounded WebDriverSessionNotCreatedError; no browser pass or presentation surface was reached. Therefore presentation apply, page-observed target, browser-computed semantics, native interaction/outcome, reset, original-baseline re-observation, and session/profile cleanup are not browser GREEN.

Issue #292 remains buyer acceptance owner; #212/.github owns Chromium workflow/sandbox mechanics; #148 owns bounded ChromeDriver startup diagnosis. This PR consumes those authorities without copying or weakening them.

No self-approval, protection bypass, workflow/ruleset/secret mutation, runtime silent repin, sandbox weakening, --no-sandbox, browser trial reduction, protected-main merge, tag, or release is part of this integration.

Summary by CodeRabbit

  • 새 기능

    • 브라우저 프레젠테이션 프로필을 명시적으로 검증하고 다이제스트로 재현할 수 있습니다.
    • 제한된 지문 정규화 및 User-Agent Client Hints 검증을 지원합니다.
    • WebDriver BiDi에서 검증된 뷰포트·DPR·시간대 명령 계획과 정리 계획을 제공합니다.
    • 화면 영역 설정은 명시적 소유권이 확인된 경우에만 지원되며, 불완전한 화면 표면은 안전하게 거부됩니다.
  • 문서

    • 프레젠테이션 정체성, BiDi 호환성, 보안 경계 및 운영 제한을 관련 문서에 반영했습니다.
  • 테스트

    • 프로필 일관성, 다이제스트 재생, 지문 표면, Client Hints 및 BiDi 계약 검증을 추가했습니다.

@coderabbitai

coderabbitai Bot commented Aug 26, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

명시적 브라우저 프레젠테이션 프로필과 제한된 fingerprint 표면을 검증하는 Rust 커널을 추가했습니다. 버전 고정 WebDriver BiDi 명령 계획과 화면 영역 소유권 경계를 추가했습니다. 관련 아키텍처, 정책, ADR, 제품 문서 및 계약 테스트를 갱신했습니다.

Changes

프레젠테이션 정체성 및 WebDriver BiDi 경계

Layer / File(s) Summary
프레젠테이션 커널 및 다이제스트
Cargo.toml, crates/originweave-fingerprint/..., tests/test_fingerprint_dependency_pin_contract.py
PresentationProfile이 명시적 화면, viewport, DPR, 동시성, timezone, 플랫폼, 언어 및 reduced-motion 값을 검증합니다. canonical serialization과 SHA-256 다이제스트를 생성하며 replay에서 불일치 다이제스트를 거부합니다.
Stealth 및 UA Client Hints 표면
crates/originweave-fingerprint/src/stealth.rs, crates/originweave-fingerprint/src/ua_hints.rs, crates/originweave-fingerprint/tests/*surface.rs, docs/adr/0111-*, docs/adr/0112-*
Canvas, WebGL, WebAudio, WebRTC 및 UA Client Hints를 제한된 열거형과 입력 검증으로 모델링합니다. 필수 표면이 없으면 fail-closed 결과를 반환합니다.
버전 고정 WebDriver BiDi 명령 계획
crates/originweave-bidi/..., docs/adr/0107-*, docs/adr/0113-*, README.md, docs/product-roadmap.md
2026-09-03 WebDriver BiDi 기준을 고정합니다. planner는 검증된 viewport, DPR, timezone에 대한 apply 및 cleanup 명령만 생성합니다. 화면 영역 명령은 불투명한 소유권 증명이 필요합니다. 완전한 프로필 승인은 MissingSurface(Screen)으로 실패합니다.
정책, 문서 및 저장소 계약
ARCHITECTURE.md, docs/PRD.md, docs/TRD.md, docs/adr/*, docs/doctoring*, docs/traceability/*, CHANGELOG.md, AGENTS.md, CLAUDE.md, tests/test_*contract.py
기본 프로필 선택, 브라우저 표면 적용, 우회 금지, BiDi planning과 실행 증거의 분리를 문서화합니다. ADR provenance, workspace 멤버, 의존성 고정 및 문서 상태 계약을 테스트합니다.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Caller
  participant PresentationProfile
  participant WebDriverBidiPlanner
  participant BrowserTransport
  Caller->>PresentationProfile: 명시적 프로필 값 검증
  PresentationProfile-->>Caller: 검증된 presentation 값 반환
  Caller->>WebDriverBidiPlanner: viewport, DPR, timezone 전달
  WebDriverBidiPlanner-->>Caller: apply 및 cleanup 명령 계획 반환
  Caller->>BrowserTransport: 계획된 명령 전달
  BrowserTransport-->>Caller: transport와 page-observed 증거를 별도 처리
Loading

Merge Risk: 🟡 Moderate · up to cfb58

The new presentation planner can overwrite and then clear existing viewport, DPR, or timezone overrides in a reused browser context, potentially altering another workflow’s browser state. Require ownership or predecessor restoration before merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 90.97% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 155 functions across 22 files. (8 skipped: …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 프라이버시 보호형 presentation identity kernel 추가라는 주요 변경을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/privacy-presentation-identity

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Review follow-up on exact head eae6ccd: format_ratio now exhaustively matches DevicePixelRatio, and explicit replay accepts only the enumerated language classes. I did not add the suggested set_size == 0 return: returning index 0 would still panic when derive indexes the empty eligible vector, so it is not a valid fail-closed fix. The private derivation sets retain a regression that proves every screen admits at least one enumerated viewport width and height. Full workspace tests, strict Clippy, rustdoc, 144 documentation tests, and 100% production function/line/region/branch coverage pass locally.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

github-advanced-security[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

…recovery-required

fix: quarantine uncertain Browser Session creation

Copy link
Copy Markdown
Contributor Author

Writer handoff / stale-lease recovery — prior source lease 5611558207 began at cfb58600a2253b6f1751f5252f4aabfbec6e9cc1 on 2026-09-10 02:03:54Z and has no matching RELEASE, but the branch subsequently advanced to 7ec83c1be1a8e8724d37c2d6ebbdb215b1b10e23 and has remained there while its owned finding was superseded by the reviewed Browser Session lifecycle stack. I am treating that old marker as orphaned, not as evidence of concurrent work.

Scope for this handoff is only ordinary adoption of #313 exact bab489ab244e0edfdb309692ee1f9ecd2e7adde0 into the unchanged #229 head. #313 has fresh exact-parent CI 34476233914 GREEN (Rust contracts 102867553488; exact production coverage 102867553175), CodeRabbit reviewed that exact parent head with no blocking Browser Session finding, and its sole inline thread PRRT_kwDOTulPlM6g8caN is now resolved after verifying the adopted RecoveryRequired/recovery-evidence fix on the parent source. I will use expected-head ordinary merge only; no force/destructive restack, protected-main merge, workflow/ruleset/secret change, runtime repin, provider/model change, sandbox weakening, tag or release.

…-lifecycle-authority

feat: add Browser Session lifecycle authority

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • AGENTS.md — repository behavior
  • ARCHITECTURE.md — repository behavior
  • CHANGELOG.md — repository behavior
  • CLAUDE.md — repository behavior
  • Cargo.lock — Rust workspace or package manifest
  • Cargo.toml — Rust workspace or package manifest
  • README.md — repository behavior
  • crates/originweave-bidi/Cargo.toml — Rust workspace crate API and tests
  • crates/originweave-bidi/src/lib.rs — Rust workspace crate API and tests
  • crates/originweave-bidi/src/presentation_capabilities.rs — Rust workspace crate API and tests
  • crates/originweave-browser-session/Cargo.toml — Rust workspace crate API and tests
  • crates/originweave-browser-session/src/lib.rs — Rust workspace crate API and tests
  • crates/originweave-browser-session/tests/destroy_failure_requires_recovery.rs — Rust workspace crate API and tests
  • crates/originweave-browser-session/tests/sequential_incarnation_reuse.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/Cargo.toml — Rust workspace crate API and tests
  • crates/originweave-fingerprint/src/lib.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/src/stealth.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/src/ua_hints.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/tests/kernel_contract.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/tests/presentation.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/tests/replay_digest.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/tests/stealth_noise_surface.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/tests/surface_admission.rs — Rust workspace crate API and tests
  • crates/originweave-fingerprint/tests/ua_client_hints_surface.rs — Rust workspace crate API and tests
  • docs/PRD.md — operator or user guidance
  • docs/README.md — operator or user guidance
  • docs/TRD.md — operator or user guidance
  • docs/adr/0107-browser-protocol-adapter-strategy.md — operator or user guidance
  • docs/adr/0108-crawler-policy.md — operator or user guidance
  • docs/adr/0110-privacy-preserving-presentation-identity.md — operator or user guidance
  • docs/adr/0111-bounded-stealth-normalization-surfaces.md — operator or user guidance
  • docs/adr/0112-bounded-user-agent-client-hints.md — operator or user guidance
  • docs/adr/0113-webdriver-bidi-screen-area-ownership.md — operator or user guidance
  • docs/adr/0114-browser-session-disposable-context-authority.md — operator or user guidance
  • docs/adr/README.md — operator or user guidance
  • docs/doctoring.md — operator or user guidance
  • docs/doctoring/webdriver-bidi-screen-area.md — operator or user guidance
  • docs/product-roadmap.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • docs/traceability/browser-session-lifecycle-authority.md — operator or user guidance
  • docs/traceability/webdriver-bidi-publication-current.md — operator or user guidance
  • docs/traceability/webdriver-bidi-screen-area-planning.md — operator or user guidance
  • docs/uml/browser-session-lifecycle-authority.md — operator or user guidance
  • tests/test_adr_index_provenance.py — regression suite
  • tests/test_bidi_media_authority_contract.py — regression suite
  • tests/test_browser_session_lifecycle_contract.py — regression suite
  • tests/test_fingerprint_dependency_pin_contract.py — regression suite
  • tests/test_presentation_identity_documentation_contract.py — regression suite
  • tests/test_presentation_selection_contract.py — regression suite
  • tests/test_repository_contract.py — regression suite
  • tests/test_webdriver_bidi_docs_currentness_contract.py — regression suite
  • tests/test_webdriver_bidi_presentation_adapter_contract.py — regression suite
  • tests/test_webdriver_bidi_screen_settings_contract.py — regression suite

Changed behavior

classDiagram
  class WebDriverBidiCommandError
  class WebDriverBidiBrowsingContext
  class new
  class as_str
  class WebDriverBidiPresentationOwnership
  class WebDriverBidiScreenArea
  class WebDriverBidiScreenAreaOwnership
  class WebDriverBidiPresentationCommand
Loading

Changed API

  • WebDriverBidiCommandError
  • WebDriverBidiBrowsingContext
  • new
  • as_str
  • WebDriverBidiPresentationOwnership
  • WebDriverBidiScreenArea
  • WebDriverBidiScreenAreaOwnership
  • WebDriverBidiPresentationCommand
  • plan_standard_presentation_commands
  • plan_standard_presentation_cleanup
  • require_complete_presentation_profile
  • BrowserSessionState
  • BrowserSessionError
  • DisposableContextCreateError
  • DisposableContextDestroyError
  • DisposableIsolationIdError
  • DisposableIsolationId
  • parse
  • BrowserSessionIncarnation
  • DisposableContextHandle
  • isolation
  • BrowserSessionRecoveryEvidence
  • DisposableContextPort
  • BrowserContextEpoch
  • PresentationMutationAuthority
  • BrowserSession
  • start
  • recovery_evidence
  • create_disposable_context
  • presentation_authority
  • advance_context_epoch
  • destroy_disposable_context
  • record_transport_loss
  • end
  • PresentationError
  • PresentationSurface
  • require_presentation_surfaces
  • ScreenMetrics
  • ViewportBounds
  • DevicePixelRatio
  • from_ratio
  • PresentationPlatform
  • PresentationTimeZone
  • PresentationDigest
  • PresentationProfile
  • replay
  • languages
  • digest
  • StealthSurface
  • require_stealth_surfaces
  • StealthError
  • CanvasNoise
  • WebGlRendererToken
  • canonical
  • WebAudioRate
  • normalize
  • WebRtcInterface
  • exposes_candidates
  • ClientHintsError
  • UaBrand
  • name
  • version
  • HintsArchitecture
  • from_token
  • HintsBitness
  • HintsPlatform
  • UaClientHints
  • model
  • brands

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 6d87dff5dc572fbd74d06309d574a998f23cf02f
  • Workflow run: 34477214979
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

classDiagram
  class WebDriverBidiCommandError
  class WebDriverBidiBrowsingContext
  class new
  class as_str
  class WebDriverBidiPresentationOwnership
  class WebDriverBidiScreenArea
  class WebDriverBidiScreenAreaOwnership
  class WebDriverBidiPresentationCommand
Loading

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants